reverse-engineering

Warn

Audited by Socket on Sep 15, 2026

5 alerts found:

Securityx3Anomalyx2
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally coherent for reverse engineering, but it gives an AI agent explicit offensive-security capabilities including exploit development, anti-debug bypass, SSL unpinning, and interception. No direct malware or credential theft is shown in the excerpt, yet the optional third-party MCP/live-query integrations add meaningful supply-chain and transitive-trust risk.

Confidence: 89%Severity: 81%
AnomalyLOW
references/firmware-embedded.md

The shown portion is dual-use IoT firmware security and reverse-engineering documentation. It contains potentially dangerous commands for scanning devices, accessing bootloaders, dumping flash, bypassing bootloader settings, and erasing or rewriting firmware, but no direct evidence of malware, covert exfiltration, persistence, or supply-chain sabotage. Use should be restricted to authorized devices and environments.

Confidence: 96%Severity: 58%
SecurityMEDIUM
references/frida.md

The supplied material is a dual-use Frida scripting reference, not executable malware by itself. It contains high-impact techniques for secret extraction, traffic interception, security-control bypass, memory modification, and process injection. Use against unauthorized applications would create substantial security and legal risk, but the fragment contains no autonomous malicious payload or covert exfiltration mechanism.

Confidence: 98%Severity: 72%
AnomalyLOW
references/managed-code-re.md

The fragment is reverse-engineering and runtime-instrumentation guidance, not clear standalone malware. It contains explicit license-bypass behavior and an unsafe example that logs passwords, creating significant misuse and credential-exposure risk when applied to third-party software. No direct exfiltration or persistence is shown. Assessment is limited to the visible fragment.

Confidence: 97%Severity: 68%
SecurityMEDIUM
references/ios-re.md

This is offensive mobile-security tooling or a penetration-testing guide rather than normal application-library code. It contains explicit mechanisms to bypass TLS validation and jailbreak detection and instructions to extract keychain and application data. No direct exfiltration or malware payload is visible in the supplied fragment, so malicious intent cannot be established solely from this excerpt; nevertheless, the operational security risk is high because these techniques can defeat confidentiality and application security controls.

Confidence: 98%Severity: 90%
Audit Metadata
Analyzed At
Sep 15, 2026, 06:22 PM
Package URL
pkg:socket/skills-sh/r00tedbrain-backup%2Fskills%2Freverse-engineering%2F@c0f84a17750e03c4b75e8e0440b48737e92847936b34d5bb3dda3af3051a2669
Security Audit — socket — reverse-engineering