ios-pentesting-tricks

Fail

Audited by Socket on Jul 21, 2026

2 alerts found:

SecurityMalware
SecurityMEDIUM
SKILL.md

High-risk but not confirmed malware. The skill is internally consistent as an iOS pentesting playbook, yet its actual footprint equips an AI agent with offensive security capabilities, sensitive credential extraction workflows, and transitive loading of related skills. The main concerns are exploit-tool enablement and third-party tool trust, not covert exfiltration or deception.

Confidence: 92%Severity: 84%
MalwareHIGH
IOS_RUNTIME_TRICKS.md

This fragment is strongly indicative of malicious or unauthorized tooling: it forcibly bypasses `PaymentManager` receipt validation by always returning success, and it selectively intercepts authentication/session-related notifications and logs their `userInfo` payloads, which can include tokens or session data. Use of runtime method replacement/interception and the explicit bypass behavior make this a high security risk.

Confidence: 85%Severity: 90%
Audit Metadata
Analyzed At
Jul 21, 2026, 01:26 PM
Package URL
pkg:socket/skills-sh/strivepan-svg%2Fhack-skills%2Fios-pentesting-tricks%2F@762a3c501726003ddb2774ed1c81bbce060b0c812676682a1b477f959baac416
Security Audit — socket — ios-pentesting-tricks