bypassing-mobile-pinning

Warn

Audited by Socket on Jul 30, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally coherent as a mobile app security-testing guide, and most referenced tools come from legitimate sources, so it is not malware. However, it gives an AI agent explicit offensive capability to defeat TLS pinning, redirect traffic, patch apps, and handle client-cert material, which makes it high security risk by scope despite acceptable install trust.

Confidence: 90%Severity: 82%
Audit Metadata
Analyzed At
Jul 30, 2026, 01:19 AM
Package URL
pkg:socket/skills-sh/trilwu%2Fsecskills%2Fbypassing-mobile-pinning%2F@87708c36d0221f98b8846b23721b3f2c2056ec80ba21240240ab80f5b93e4af5
Security Audit — socket — bypassing-mobile-pinning