renef

Fail

Audited by Socket on Jul 14, 2026

4 alerts found:

Securityx2Malwarex2
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally coherent and the Renef provenance appears legitimate, but its purpose is to give an AI agent offensive Android instrumentation powers: hooking, memory patching, SSL/root bypass, crypto-key logging, and cheats. The main risk is not deceptive supply chain behavior; it is that this skill materially enables exploit/reverse-engineering actions against live apps and devices.

Confidence: 89%Severity: 86%
MalwareHIGH
references/recipes.md

High confidence malicious intent. The code is an offensive instrumentation script that disables TLS certificate validation across multiple stacks (TrustManager/OkHttp/Flutter/libssl/WebView), evades root detection by blocking libc calls and spoofing system properties, and performs explicit cryptographic key logging by extracting AES keys from libcrypto and printing them. It also includes memory scanning/patching capabilities to tamper with runtime behavior. This should not be used in any production or security-sensitive environment.

Confidence: 95%Severity: 95%
MalwareHIGH
references/methodology.md

This fragment is highly suspicious offensive guidance for using a hooking framework to bypass mobile app security controls, with explicit targeting of TLS/SSL and WebView/HTTP trust verification paths across common stacks (including native Flutter BoringSSL). It describes concrete runtime tampering actions (hooking, forcing return values, skipping checks, native instruction patching, late-load hooking) and verification via proxy-observed network behavior. Even without executable payload code in the excerpt, the described capability is aligned with intrusion/interception and would be dangerous if included in a software dependency.

Confidence: 78%Severity: 90%
SecurityMEDIUM
references/from-other-tools.md

This fragment is high-risk supply-chain material if distributed as a dependency because it provides practical, example-driven capability for runtime process injection/hooking, repeated memory value tampering (“freeze/edit”), instruction patching (ARM64 NOP/return forcing), and behavior bypass via args.skip/return override. It does not show explicit exfiltration or persistence in the snippet, but the demonstrated in-process tampering primitives have strong unauthorized-use alignment and can directly undermine app/game integrity and potentially security-sensitive logic in the target.

Confidence: 71%Severity: 90%
Audit Metadata
Analyzed At
Jul 14, 2026, 06:32 PM
Package URL
pkg:socket/skills-sh/vichhka-git%2Frenef-skills%2Frenef%2F@f558619dec3fc860d0eaccad2b7eaadeeb76dcf5813de948acc6d139ed1641dc
Security Audit — socket — renef