mobile-insecure-storage

Warn

Audited by Socket on Sep 22, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally coherent as a mobile security-testing skill, but it grants an AI agent offensive app-assessment capabilities and uses several external tools that can extract sensitive device/app data. Data flows stay local and there is no clear credential harvesting or remote exfiltration, so this is not confirmed malware; however, the exploit-oriented purpose and third-party toolchain make it high security risk.

Confidence: 92%Severity: 82%
Audit Metadata
Analyzed At
Sep 22, 2026, 05:36 PM
Package URL
pkg:socket/skills-sh/securityfortech%2Fhacking-skills%2Fmobile-insecure-storage%2F@7e301152f39d853571346c3ff44b5d8f6319cc5a740f458e2b38e1ae347970b8
Security Audit — socket — mobile-insecure-storage