ios-pentesting-tricks
Audited by Socket on Jul 21, 2026
2 alerts found:
SecurityMalwareHigh-risk but not confirmed malware. The skill is internally consistent as an iOS pentesting playbook, yet its actual footprint equips an AI agent with offensive security capabilities, sensitive credential extraction workflows, and transitive loading of related skills. The main concerns are exploit-tool enablement and third-party tool trust, not covert exfiltration or deception.
This fragment is strongly indicative of malicious or unauthorized tooling: it forcibly bypasses `PaymentManager` receipt validation by always returning success, and it selectively intercepts authentication/session-related notifications and logs their `userInfo` payloads, which can include tokens or session data. Use of runtime method replacement/interception and the explicit bypass behavior make this a high security risk.