ghidra-reverse

Warn

Audited by Socket on Jul 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core Ghidra use is coherent with the stated purpose, but the optional 'ghidra-mcp' bootstrap is under-specified and points to unverifiable third-party choices. Combined with giving an AI agent reverse-engineering capability that can feed exploit workflows, this is a high security-risk skill even without clear malicious intent.

Confidence: 86%Severity: 76%
Audit Metadata
Analyzed At
Jul 18, 2026, 08:16 AM
Package URL
pkg:socket/skills-sh/zhaoxuya520%2Freverse-skill%2Fghidra-reverse%2F@1105f9cf3749acbefe01ba3bfa7dd7c312b240ff07a02185a05c1ffdea35857b
Security Audit — socket — ghidra-reverse