reverse-engineering

Warn

Audited by Socket on Sep 4, 2026

3 alerts found:

Securityx2Anomaly
SecurityMEDIUM
SKILL.md

The skill is internally consistent with a reverse-engineering purpose and does not show clear credential theft or deceptive exfiltration. However, it grants an AI agent a high-risk offensive analysis toolkit—debugging, binary patching, anti-analysis bypass, sample execution, and malware-adjacent workflows—so it should be treated as a suspicious/high-risk security skill rather than benign documentation.

Confidence: 92%Severity: 78%
SecurityMEDIUM
dsl-vm-reverse/SKILL.md

SUSPICIOUS. The skill is internally coherent, but its stated purpose is to reverse risk-control systems and automate anti-detection browser actions to recover tokens. There is no clear credential theft or malicious installer, yet the capability set is high-risk offensive tooling for an AI agent and can enable bypass of anti-bot or fraud controls.

Confidence: 87%Severity: 76%
AnomalyLOW
platforms.md

The provided fragment is high-risk dual-use offensive content. It contains a concrete Frida-based jailbreak-detection bypass that intercepts `access()` and forces failure (`retval.replace(-1)`) for known jailbreak-related paths, plus extensive step-by-step guidance for dynamic instrumentation/injection concepts, firmware extraction, kernel/driver/eBPF reversing, and automotive RE. The fragment does not, by itself, demonstrate credential theft, persistence, or data exfiltration, but it clearly enables evasion and follow-on attack development. Treat as potentially malicious/attack-enabling unless verified as non-executed documentation within a benign repository.

Confidence: 60%Severity: 65%
Audit Metadata
Analyzed At
Sep 4, 2026, 01:54 PM
Package URL
pkg:socket/skills-sh/zhaoxuya520%2Freverse-skill%2Freverse-engineering%2F@4e01740d6f455b78f1598aa88c23fe4a490e774cbf5a3f0e3dc5e44a618d0aa9
Security Audit — socket — reverse-engineering