mobile-security

Warn

Audited by Socket on May 13, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
reference/flutter-aot-reversing.md

No direct malware is present in this fragment because it is instructional text, not a runnable payload. However, it is highly actionable and offense-oriented: it instructs reverse-engineering of Flutter AOT logic and explicitly covers patching to disable TLS pinning plus using Frida, along with guidance for reconstructing encrypted payment/banking request envelopes and abusing request parameters. Treat as high misuse potential rather than a benign dependency artifact.

Confidence: 80%Severity: 75%
SecurityMEDIUM
SKILL.md

BENIGN in intent alignment but HIGH RISK in capability class: the skill consistently describes mobile app security testing and reverse engineering, with no obvious credential harvesting or exfiltration path in the supplied text. The main concern is that it gives an AI agent offensive mobile security workflows, including bypass techniques, which is inherently dangerous even though it is internally coherent.

Confidence: 89%Severity: 72%
Audit Metadata
Analyzed At
May 13, 2026, 10:32 PM
Package URL
pkg:socket/skills-sh/transilienceai%2Fcommunitytools%2Fmobile-security%2F@aa9c7d5e5210c342777824c0a4ed2d7908de3fc6
Security Audit — socket — mobile-security