skills/mukul975/anthropic-cybersecurity-skills/performing-thick-client-application-penetration-test/Socket
performing-thick-client-application-penetration-test
Warn
Audited by Socket on Apr 7, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally coherent as a thick-client pentesting guide, but it gives an AI agent high-risk offensive security capabilities including auth bypass, SSL pinning bypass, DLL hijacking, memory tampering, and API abuse testing. Install provenance is mostly acceptable for named tools, with minor uncertainty around external Frida scripts; the primary concern is the exploit-focused operational scope rather than deceptive data exfiltration.
Confidence: 92%Severity: 91%
Audit Metadata