offensive-mobile
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS/HIGH-RISK skill. The content is internally consistent with its stated offensive mobile pentest purpose and shows no clear credential harvesting, stealth, or exfiltration to attacker-controlled endpoints, so it is not confirmed malware. However, it materially equips an AI agent to perform penetration testing, bypass security controls, intercept traffic, inspect protected app data, and tamper with apps; this offensive capability alone makes the skill high risk. Supply-chain concerns are secondary: most tools cited are legitimate open-source projects, but trust is weaker for community CodeShare scripts and the third-party Magisk CA helper.
Confidence: 92%Severity: 78%
Audit Metadata