mobile-pentest
Audited by Socket on Sep 17, 2026
2 alerts found:
SecurityMalwareSUSPICIOUS: the skill is internally coherent for mobile app pentesting, but it equips an AI agent with high-risk offensive security capabilities, including bypass and data-extraction steps. Install sources appear mostly legitimate though unpinned; the main concern is the breadth and intrusiveness of the agent's testing power rather than hidden malware or covert exfiltration.
This fragment is penetration-testing/offensive tooling rather than benign dependency code. It contains high-misuse-capability snippets: an Android universal TLS pinning/trust verification bypass (via Frida hooks/overrides) and an iOS hook targeting the Keychain credential access API (SecItemCopyMatching) with logging. While the Python report generator itself is benign and no exfiltration/persistence is shown, the included bypass/instrumentation capabilities make the overall content highly dangerous if shipped as part of a software supply chain dependency or executed outside authorized testing.