reverse-engineering
Audited by Socket on Sep 4, 2026
3 alerts found:
Securityx2AnomalyThe skill is internally consistent with a reverse-engineering purpose and does not show clear credential theft or deceptive exfiltration. However, it grants an AI agent a high-risk offensive analysis toolkit—debugging, binary patching, anti-analysis bypass, sample execution, and malware-adjacent workflows—so it should be treated as a suspicious/high-risk security skill rather than benign documentation.
SUSPICIOUS. The skill is internally coherent, but its stated purpose is to reverse risk-control systems and automate anti-detection browser actions to recover tokens. There is no clear credential theft or malicious installer, yet the capability set is high-risk offensive tooling for an AI agent and can enable bypass of anti-bot or fraud controls.
The provided fragment is high-risk dual-use offensive content. It contains a concrete Frida-based jailbreak-detection bypass that intercepts `access()` and forces failure (`retval.replace(-1)`) for known jailbreak-related paths, plus extensive step-by-step guidance for dynamic instrumentation/injection concepts, firmware extraction, kernel/driver/eBPF reversing, and automotive RE. The fragment does not, by itself, demonstrate credential theft, persistence, or data exfiltration, but it clearly enables evasion and follow-on attack development. Treat as potentially malicious/attack-enabling unless verified as non-executed documentation within a benign repository.