headless-ghidra-baseline

Warn

Audited by Socket on May 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s reverse-engineering capabilities are broadly consistent with its stated purpose, but it hinges on an unverified `ghidra-agent-cli` wrapper that mediates all Ghidra/Frida actions. There is no explicit credential harvesting or exfiltration in the supplied text, yet the required opaque CLI and security-tooling nature make the skill high risk overall.

Confidence: 81%Severity: 76%
Audit Metadata
Analyzed At
May 1, 2026, 12:53 AM
Package URL
pkg:socket/skills-sh/ByteLandTechnology%2Fheadless-ghidra%2Fheadless-ghidra-baseline%2F@9df05f530ac1a097d7427659f636e0dae8c77fd9