mobile-reverse

Fail

Audited by Socket on Sep 2, 2026

4 alerts found:

Securityx2Malwarex2
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill: its capabilities align with its stated mobile reverse-engineering purpose, so it is not deceptive, but it materially increases attack capability by enabling bypasses, runtime instrumentation, traffic interception, and secret extraction. This is best classified as a high-risk offensive security skill rather than malware.

Confidence: 92%Severity: 82%
SecurityMEDIUM
references/ios-reverse-guide.md

This fragment is a reverse-engineering and security-bypass guide (not a typical npm/PyPI dependency). It provides concrete Frida hook implementations that actively defeat jailbreak/sandbox, anti-injection/dyld heuristics, and anti-debug checks by altering return values and replacing system functions. While there is no evidence of cryptomining, credential theft, or network exfiltration in the snippet, the intent and mechanics strongly enable bypassing security controls, making it high-risk from a misuse perspective. Lack of a real package/dependency makes malware-within-a-package unprovable, but the security risk of the provided techniques is substantial.

Confidence: 62%Severity: 78%
MalwareHIGH
references/frida-objection-deep.md

This fragment is explicitly designed to bypass TLS certificate pinning and trust verification on both Android and iOS by hooking and overriding security-critical runtime functions and forcing success/proceed outcomes. While it does not directly show exfiltration in this snippet, it provides a high-impact capability commonly used to enable MITM interception and undermine HTTPS security. Treat as dangerous and unsuitable for inclusion in any trusted dependency.

Confidence: 90%Severity: 99%
MalwareHIGH
references/anti-detection-bypass.md

High-risk and strongly indicative of malicious/offensive capability. The fragment provides explicit, multi-layer runtime bypasses for root/jailbreak detection and anti-debugging checks on Android and iOS, and most critically disables TLS certificate/pinning validation across multiple networking stacks by forcing trust decisions to succeed. If present in a software supply-chain dependency, it would materially enable stealth instrumentation and TLS MITM/credential interception workflows. Obfuscation is not evident; the danger is in direct tampering of security-critical outcomes. Additional context is needed to confirm whether this code actually executes in the package, but the described behaviors are inherently unsafe.

Confidence: 86%Severity: 98%
Audit Metadata
Analyzed At
Sep 2, 2026, 06:23 PM
Package URL
pkg:socket/skills-sh/sickn33%2Fagentic-awesome-skills%2Fmobile-reverse%2F@cf5e8cd22df4f7e6d093cf7c6e799c6940507baaed444dd6efb7a88ffa617c3e
Security Audit — socket — mobile-reverse