apk-reverse

Fail

Audited by Socket on Sep 1, 2026

3 alerts found:

Securityx2Malware
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally consistent with its stated reverse-engineering purpose, but that purpose itself grants offensive capability to an AI agent: app modification, Frida injection, SSL/root-bypass work, and device installation. The main security concern is proportionality and execution risk, plus automatic installation of third-party tools from multiple external sources without strong verification. No clear credential harvesting or covert exfiltration is shown, so this is not confirmed malware, but it is a high-risk offensive skill.

Confidence: 91%Severity: 83%
SecurityMEDIUM
references/frida-bypass-kit.md

The reviewed fragment does not include the actual Frida script code, but it clearly describes a turnkey runtime bypass kit that can disable root/emulator/anti-debug checks and bypass TLS certificate-chain validation/SSL pinning by hooking TrustManagerImpl methods. This functionality is highly dual-use and materially increases misuse potential, especially due to the claimed certificate-validation bypass. No direct evidence of extra malware behaviors (exfiltration, persistence, etc.) is present in the fragment, but such behaviors cannot be ruled out without inspecting the real script.

Confidence: 60%Severity: 82%
MalwareHIGH
references/android-advanced.md

This fragment is highly indicative of malicious or at least strongly abuse-capable behavior: it performs live instrumentation to disable TLS certificate pinning/peer verification (OkHttp and native Flutter paths) and to evade root/debug/integrity checks (File.exists and System.getProperty overrides, plus native function replacement). In a supply-chain context, inclusion of such code would represent a severe security risk because it can enable MITM attacks and bypass app integrity controls.

Confidence: 90%Severity: 95%
Audit Metadata
Analyzed At
Sep 1, 2026, 03:50 PM
Package URL
pkg:socket/skills-sh/sickn33%2Fagentic-awesome-skills%2Fapk-reverse%2F@af8fcefd0b45510a9b98c408cd845664e6d786758653d3532b34c330af3c08aa
Security Audit — socket — apk-reverse