performing-firmware-extraction-with-binwalk

Warn

Audited by Socket on Sep 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill is internally coherent for firmware analysis, and most commands are standard for that purpose, but it materially equips an AI agent with offensive security/reverse-engineering capabilities. Install trust is mixed: PyPI/system-package usage is normal, yet `binwalk3` is not the upstream publisher's main documented path and `sasquatch` appears to rely on a personal-repo distribution model. No clear credential exfiltration or malicious data routing is present, so this is high-risk vulnerable capability rather than confirmed malware.

Confidence: 94%Severity: 76%
Audit Metadata
Analyzed At
Sep 7, 2026, 10:28 PM
Package URL
pkg:socket/skills-sh/plurigrid%2Fasi%2Fperforming-firmware-extraction-with-binwalk%2F@5e16f9a141c23bfc32acdfd7c9b22fca1f6f6618a95bbf70290a569fb0dc79d4
Security Audit — socket — performing-firmware-extraction-with-binwalk