mobile-reverse

Fail

Audited by Socket on Jul 18, 2026

4 alerts found:

Securityx2Malwarex2
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent as a mobile reverse-engineering guide, but its actual footprint is a high-risk offensive security capability set for an AI agent. The main concern is not hidden malware or odd data routing; it is that the skill enables active bypass, interception, instrumentation, and secret extraction on apps and devices.

Confidence: 89%Severity: 86%
SecurityMEDIUM
references/ios-reverse-guide.md

This module is best characterized as high-risk dual-use security-evasion tooling. It provides actionable steps to decrypt iOS apps and uses Frida and DYLD_INSERT_LIBRARIES to falsify security-relevant runtime signals (jailbreak/debug/instrumentation and related checks). No explicit data theft or persistence is shown, but the capability substantially enables bypass of defensive controls, which can facilitate unauthorized tampering or downstream compromise. Treat as suspicious and restrict use to authorized research/testing environments.

Confidence: 75%Severity: 88%
MalwareHIGH
references/frida-objection-deep.md

The provided fragment is high-risk offensive instrumentation guidance. It demonstrates how to hook Java/Native/ObjC execution, exfiltrate runtime details via logging, and—most importantly—bypass security controls by tampering with return values (root/jailbreak detection, strcmp-based logic) and overriding TLS certificate/trust enforcement (SSL pinning bypass). It also includes workflows for patching and re-signing mobile apps to inject Frida Gadget, indicating capability for stealthy runtime manipulation of distributed binaries. Overall, this content is strongly aligned with malicious intrusion/tampering use cases rather than benign functionality.

Confidence: 86%Severity: 97%
MalwareHIGH
references/anti-detection-bypass.md

This fragment is highly consistent with malicious or abuse-enabling supply-chain content: it provides step-by-step Frida/Objection techniques to bypass Android/iOS root/jailbreak detection and anti-debugging, and it explicitly disables TLS pinning/certificate validation across multiple stacks. If present in a dependency, it would represent a severe security risk because it can materially enable stealth instrumentation and MITM-capable interception of application traffic while evading integrity and debug protections.

Confidence: 86%Severity: 100%
Audit Metadata
Analyzed At
Jul 18, 2026, 08:19 AM
Package URL
pkg:socket/skills-sh/zhaoxuya520%2Freverse-skill%2Fmobile-reverse%2F@4312e3bbbe825582cee50b0af805f4c6195a8ff6fe69f96d1db7de770781e843
Security Audit — socket — mobile-reverse