firmware-analyst

Warn

Audited by Socket on May 3, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
references/binary-analysis-patterns.md

SUSPICIOUS: The skill is internally consistent and does not show credential theft, exfiltration, or installer abuse, but it equips an AI agent with offensive-adjacent reverse-engineering capability. Risk is driven by the nature of the capability, not by malicious data flows or supply-chain behavior in the skill itself.

Confidence: 93%Severity: 58%
SecurityMEDIUM
SKILL.md

Purpose and capabilities are internally consistent for a firmware security research skill, with no clear credential harvesting or exfiltration path. However, it equips an AI agent with meaningful offensive security and exploit-analysis workflows, so it is not malicious but is high-risk as an exploit-oriented skill.

Confidence: 90%Severity: 71%
Audit Metadata
Analyzed At
May 3, 2026, 06:23 PM
Package URL
pkg:socket/skills-sh/itsimonfredlingjack%2Fcodex-dev-plugin%2Ffirmware-analyst%2F@619d94157afa4dea20e65391a337ce3e69857c0b
Security Audit — socket — firmware-analyst