symmetric-cipher-attacks

Warn

Audited by Socket on Jul 21, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent as an offensive cryptanalysis playbook, but its actual purpose is to equip an AI agent with exploit techniques against remote targets. There is little evidence of malware or credential theft, yet the offensive security scope makes it a high-risk skill.

Confidence: 91%Severity: 83%
AnomalyLOW
BLOCK_CIPHER_ATTACKS.md

No direct evidence of supply-chain malware (no exfiltration, backdoor/persistence, credential theft, or obfuscated runtime payloads) is present in this fragment. The security concern is dual-use misuse: it provides implementable guidance for breaking/enumerating weaknesses in common cryptographic constructions (padding oracles, malleability via CBC bit-flipping, ECB oracle attacks, PRNG state cloning, and GCM nonce-reuse exploitation). If distributed as a dependency, its main impact is enabling attackers to exploit vulnerable implementations rather than performing malicious actions itself.

Confidence: 66%Severity: 55%
Audit Metadata
Analyzed At
Jul 21, 2026, 01:27 PM
Package URL
pkg:socket/skills-sh/strivepan-svg%2Fhack-skills%2Fsymmetric-cipher-attacks%2F@40be30b3732a412be9127744ceedc645b24d3e01950d0328dea227579ebc903f
Security Audit — socket — symmetric-cipher-attacks