symmetric-cipher-attacks
Audited by Socket on Jul 21, 2026
2 alerts found:
SecurityAnomalySUSPICIOUS: the skill is internally consistent as an offensive cryptanalysis playbook, but its actual purpose is to equip an AI agent with exploit techniques against remote targets. There is little evidence of malware or credential theft, yet the offensive security scope makes it a high-risk skill.
No direct evidence of supply-chain malware (no exfiltration, backdoor/persistence, credential theft, or obfuscated runtime payloads) is present in this fragment. The security concern is dual-use misuse: it provides implementable guidance for breaking/enumerating weaknesses in common cryptographic constructions (padding oracles, malleability via CBC bit-flipping, ECB oracle attacks, PRNG state cloning, and GCM nonce-reuse exploitation). If distributed as a dependency, its main impact is enabling attackers to exploit vulnerable implementations rather than performing malicious actions itself.