android-pentesting-tricks

Fail

Audited by Socket on Jul 21, 2026

2 alerts found:

MalwareSecurity
MalwareHIGH
FRIDA_SCRIPTS.md

This fragment is a set of Frida scripts intended for offensive Android testing/instrumentation that bypasses SSL pinning, evades root detection, suppresses biometric authentication failures, and extracts sensitive data (SharedPreferences contents, cryptographic keys, plaintext/ciphertext, intent extras, WebView URLs/headers/JS, and method arguments/returns). The explicit no-op/exception-throwing hooks and widespread console logging of secrets are strong indicators of malicious capability. Treat as high-risk and do not use in production or trusted pipelines without strict review and isolation.

Confidence: 90%Severity: 95%
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally coherent as an Android pentesting guide, but its actual function is to give an AI agent offensive security capabilities, including exploitation and bypass techniques. Provenance for core tools is mixed but mostly recognizable; the larger issue is that the skill materially expands attack capability and chains into other skills.

Confidence: 91%Severity: 88%
Audit Metadata
Analyzed At
Jul 21, 2026, 01:27 PM
Package URL
pkg:socket/skills-sh/strivepan-svg%2Fhack-skills%2Fandroid-pentesting-tricks%2F@bc13f53ddcb140e6a693d5c4c9915872940241803507210d6f6752c91cf2d76a
Security Audit — socket — android-pentesting-tricks