devirtualizing-vm-protected-code

Warn

Audited by Socket on Aug 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally coherent as a reverse-engineering guide and shows no direct credential theft or exfiltration, but it equips an AI agent with high-risk protected-code devirtualization capability that can be used to defeat commercial software protections. Supply-chain risk is limited because no installer is embedded, though some referenced tooling has weaker provenance than official registry-distributed tools.

Confidence: 87%Severity: 72%
Audit Metadata
Analyzed At
Aug 7, 2026, 11:28 AM
Package URL
pkg:socket/skills-sh/trilwu%2Fsecskills%2Fdevirtualizing-vm-protected-code%2F@8063152638360d3b572ce497b6f624071aaaf283b8ad6dc14ffeb002458679da
Security Audit — socket — devirtualizing-vm-protected-code