reverse-engineering

Warn

Audited by Socket on May 13, 2026

3 alerts found:

AnomalySecurityx2
AnomalyLOW
reference/scenarios/anti-debug/isdebuggerpresent-bypass.md

No direct malware payload is shown; the fragment is an anti-anti-debug/anti-analysis instructional guide. However, it contains highly actionable guidance for defeating common Windows debugger-detection methods (PEB/IsDebuggerPresent/NtQueryInformationProcess/DRx) via in-memory patching and API falsification hooks. As a result, the primary risk is dual-use enablement of evasion, which warrants review of the surrounding package context to determine legitimacy versus malicious incorporation.

Confidence: 55%Severity: 55%
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally consistent and not deceptive about installs, credentials, or data flows, but it gives an AI agent high-risk reverse-engineering and anti-debug/instrumentation capabilities that fall into the offensive-security-tool category. Supply-chain risk is low from the provided evidence; the main risk is the capability itself.

Confidence: 89%Severity: 78%
SecurityMEDIUM
reference/scenarios/dynamic-analysis/frida-hooking.md

This content is highly dual-use and centered on runtime tampering: it demonstrates intercepting security-relevant functions and forcing outcomes via return-value replacement and function replacement, along with sensitive logging, memory inspection, and optional instruction tracing. There is no explicit persistence/exfiltration shown in the fragment itself, but its operational purpose strongly aligns with authorization/security bypass and evasion. If such material were included in a software supply chain dependency, it would be a serious review red flag. More context is needed to determine whether a specific package ships this only as documentation/examples or as executable code.

Confidence: 62%Severity: 75%
Audit Metadata
Analyzed At
May 13, 2026, 10:31 PM
Package URL
pkg:socket/skills-sh/transilienceai%2Fcommunitytools%2Freverse-engineering%2F@576973692e4e416383c146992634bc5596cb8c01
Security Audit — socket — reverse-engineering