offensive-mobile

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill. The content is internally consistent with its stated offensive mobile pentest purpose and shows no clear credential harvesting, stealth, or exfiltration to attacker-controlled endpoints, so it is not confirmed malware. However, it materially equips an AI agent to perform penetration testing, bypass security controls, intercept traffic, inspect protected app data, and tamper with apps; this offensive capability alone makes the skill high risk. Supply-chain concerns are secondary: most tools cited are legitimate open-source projects, but trust is weaker for community CodeShare scripts and the third-party Magisk CA helper.

Confidence: 92%Severity: 78%
Audit Metadata
Analyzed At
Sep 15, 2026, 01:33 PM
Package URL
pkg:socket/skills-sh/snailsploit%2Fclaude-red%2Foffensive-mobile%2F@a486a1f23bf6c06f4aa16c2928e04087ca28cc4bd3cc78662f623a2773728ce2
Security Audit — socket — offensive-mobile