reverse-skill-router
Audited by Socket on Sep 6, 2026
56 alerts found:
Securityx33Malwarex15Anomalyx8This skill is internally consistent with its stated purpose, but that purpose is to orchestrate offensive intrusion activity. It enables an AI agent to perform high-risk exploit planning and execution, credential theft, persistence, stealth, and transitive tool/skill use; authorized-use language does not reduce the operational danger. Classify as high-risk vulnerable/offensive, not confirmed malware.
SUSPICIOUS: the install sources are mostly coherent, but the skill’s actual purpose is to enable an AI agent to reverse patches into working exploits and route output into downstream attack tooling. That offensive capability is fundamentally high risk for an agent skill even without clear credential theft or covert exfiltration.
SUSPICIOUS. The skill is internally coherent for malware analysis and does not show clear credential theft or deceptive third-party routing, but it gives an AI agent substantial offensive security capability and encourages immediate execution of high-risk analysis workflows. Supply-chain risk is low-to-moderate from unpinned PyPI installs; the main concern is the inherently dangerous security-tooling scope and possible external sample disclosure to threat-intel services.
SUSPICIOUS: the skill is internally consistent with a mobile reverse-engineering purpose, but that purpose itself gives the agent high-risk offensive security capabilities: bypassing platform protections, dumping app data, and extracting cryptographic material. No direct malicious exfiltration, hidden execution, or third-party credential routing is shown in this snippet, but the operational scope is powerful and the unresolved local bootstrap/tool-index dependency adds execution-trust uncertainty.
SUSPICIOUS. The skill’s capabilities align with its stated firmware pentest purpose, but that purpose is itself a high-risk offensive security workflow for an AI agent. Data flows are mostly local and to official upstream tool sources, with no clear credential-harvesting or hidden exfiltration, so this is not confirmed malware. Risk is driven by offensive exploitation guidance, immediate-action instructions, and medium supply-chain exposure from unpinned installs and git-clone-then-execute steps.
The provided fragment is best characterized as a highly malicious post-exploitation runbook: it explicitly targets credential/secret theft (LSASS/SAM/LSA equivalents, /etc/shadow, cloud and browser credentials, git/environment leaks), supports offline credential processing, and enables remote command execution via reverse shells/C2 with dynamic interpreter execution. Even though it is not confirmed as actual dependency code, in a supply-chain context this describes behavior that would be catastrophic if packaged or triggered. Action: treat as critical malicious content and do not use/redeploy unless fully disproven in actual module code and execution paths.
This PowerShell fragment strongly increases supply-chain and execution risk: it can auto-bootstrap the idalib-mcp component by running a remote-repo install script using PowerShell with ExecutionPolicy Bypass, and it starts the supervisor with an explicit '--unsafe' flag using hidden/detached process creation. While it appears aimed at running an IDA Pro local MCP server (127.0.0.1) and includes health-check logic, the combination of (1) internet-fetched dependency installation and (2) unsafe execution semantics makes it a high-priority review target for malicious behavior and trust-boundary validation. No explicit data exfiltration is evident in this snippet alone, so malware likelihood is medium rather than high, but security risk is elevated.
SUSPICIOUS. The skill is internally aligned with offensive security and reverse-engineering, so the dangerous capabilities generally fit its stated purpose. However, it is a high-risk router that mandates immediate script execution, broad downstream tool use, and bootstrap of external security tooling; this creates substantial execution and supply-chain exposure even without clear evidence of credential theft or covert exfiltration in the provided text.
High-risk offensive security skill. Its capabilities are internally consistent with its stated EDR-bypass purpose, but that purpose gives the agent concrete defense-evasion and implant-delivery instructions on real hosts, including a PowerShell bootstrap with execution-policy bypass. Not confirmed malware from the provided text alone, but clearly a dangerous agent capability set.
SUSPICIOUS. The skill’s capabilities mostly align with its stated reverse-engineering purpose, but it is a high-risk offensive/security skill and its install trust is uneven: official-looking GitHub release paths are mixed with a stale/community Chocolatey package and community MCP extensions. No clear credential theft or exfiltration is present, so this is not confirmed malware, but the combination of malware-analysis scope, binary patching guidance, and transitive MCP/tool installation makes it a medium-to-high security risk.
SUSPICIOUS: the skill is coherent with a legitimate LLM security testing purpose, but it grants an AI agent explicit offensive security behaviors including prompt injection, jailbreaks, and system prompt extraction. Install instructions shown are mostly standard registry-based and not the main concern; the core risk is enabling agent-led red-team actions against AI systems.
The provided “code” is actually analyst-style evasion/instrumentation-bypass notes, describing anti-debug/anti-Frida/root/emulator/VM detection circumvention and signature-check removal. No executable logic, data inputs, or concrete sinks (network/file/credential theft/persistence) are present in this fragment, so supply-chain malware cannot be confirmed here. If these notes correspond to the dependency’s implementation, the security posture would be concerning; otherwise, this appears to be incomplete or non-module documentation. Request the actual package/module source files (not truncated notes) to validate sinks and data flows.
该 skill 的能力与“APK 逆向”目的基本一致,未见凭证窃取、异常外传或隐蔽执行链路;但它明确赋予 AI 代理 APK 逆向、Frida 注入、绕过校验、修改并重装应用到设备的进攻性能力,属于高风险安全工具。供应链风险中等偏低,整体更像高危但目的一致的逆向/利用工作流,而非恶意窃密 skill。
SUSPICIOUS: the offensive capabilities match the stated purpose, but that purpose is to let an AI agent perform active pentesting, including exploitation and post-exploitation. Combined with ExecutionPolicy Bypass, broad third-party tool installation, mutable/unpinned dependencies, and the pentestMCP publisher/image mismatch, this skill carries high security risk even though there is not enough evidence to call it confirmed malware.
High-confidence malicious/offensive security evasion guidance. The fragment provides concrete methods to disable or bypass Windows security telemetry (ETW Threat Intelligence and AMSI) and weaken/clear defensive logging and forensic artifacts (PowerShell logging, event logs, Prefetch, history), plus Sysmon deception techniques. This content closely matches known EDR/EDR-evasion and indicator-removal attack patterns and would materially facilitate cyber abuse.
该 skill 的能力与“SRC/漏洞赏金挖掘”目的本身是一致的,但其目的就是赋予 AI 代理真实环境下的攻防测试能力,因此整体应判为高风险而非良性开发辅助。未见明确窃密、中继转发或恶意隐藏行为,故更像高风险 offensive-security skill,而不是确认恶意软件。
SUSPICIOUS:技能目的与其浏览器/桌面自动化能力基本一致,但范围包含渗透测试、逆向 GUI 操作和抓包,属高影响自动化。主要风险来自安装信任:主流组件来源正常,但 OpenReverse 依赖个人仓库 clone 安装且验证较弱;整体不像明确恶意窃密技能,但对代理开放的执行与自动化能力较强,安全风险中高。
SUSPICIOUS. The skill’s offensive capabilities align with its pentest purpose, so this is not deceptive in the narrow sense, but it is a high-risk AI skill because it enables autonomous penetration testing, DoS-style checks, and credential forwarding through multiple third-party tools/services. Supply-chain trust is mixed, one referenced tool source is questionable, and the workflow pushes immediate execution with limited user confirmation.
This fragment and its described surrounding mechanisms strongly indicate offensive Windows EDR-evasion functionality: runtime SSN/gadget resolution enabling indirect native syscalls (bypassing user-mode hooks), with additional strategies explicitly aimed at skipping or deceiving EDR telemetry (VEH + hardware breakpoints and call stack spoofing). While the snippet is truncated and full execution context is missing, the tradecraft signals are so specific that the code is best treated as highly suspicious and potentially malicious if present in a dependency.
This fragment is highly indicative of malicious or at least strongly abuse-capable behavior: it performs live instrumentation to disable TLS certificate pinning/peer verification (OkHttp and native Flutter paths) and to evade root/debug/integrity checks (File.exists and System.getProperty overrides, plus native function replacement). In a supply-chain context, inclusion of such code would represent a severe security risk because it can enable MITM attacks and bypass app integrity controls.
High-risk, adversary-oriented guidance for EDR/telemetry evasion: it describes enumerating kernel callbacks, dumping hooked user-mode system DLL trampolines from a live process, identifying the responsible EDR components, and using the results to enable unhooking/telemetry-blinding in an implant-like scenario. While this fragment is not executable code, its described actions are directly supportive of malicious defense evasion. Treat any package containing or automating this workflow as highly suspicious and unsuitable for production use without deep independent verification.
BENIGN in purpose-capability alignment but HIGH RISK as an AI-agent skill because it grants offensive security assessment capability against cloud, container, and Kubernetes environments. Install sources appear mostly official from the supplied evidence, and there is no clear exfiltration or malware behavior, but the skill materially increases real-world attack capability and should require strong human authorization and oversight.
该 skill 与其声明用途基本一致,不像伪装成无关功能的窃密器;但它为 AI 代理提供高风险的前端逆向/Hook/去混淆能力,并通过未展示的 bootstrap 脚本安装和注册第三方 MCP 工具,存在明显供应链与执行面风险。综合判断为 SUSPICIOUS:更像高风险安全/逆向工作流,而非确认恶意软件。
SUSPICIOUS: the skill’s purpose is coherent for reverse engineering, but it relies on a third-party community plugin and runtime `npx` execution rather than an official Vector 35 integration. Data flow stays local and scoped, so this looks more like medium supply-chain risk than malicious behavior.
High-risk malicious/weaponized content: the fragment is a detailed container escape and Kubernetes cluster takeover playbook (recon->token abuse->privileged hostPath/hostNetwork pod creation->host/context execution and lateral movement), including references to known escape/kernel exploits and offensive tooling. No benign library logic is present.
This fragment is explicitly designed to bypass TLS certificate pinning and trust verification on both Android and iOS by hooking and overriding security-critical runtime functions and forcing success/proceed outcomes. While it does not directly show exfiltration in this snippet, it provides a high-impact capability commonly used to enable MITM interception and undermine HTTPS security. Treat as dangerous and unsuitable for inclusion in any trusted dependency.
This module is primarily an orchestrator for running jadx and apktool on a provided APK and extracting basic metadata. It does not show direct malicious behavior (no exfiltration/persistence/credential theft). However, it meaningfully increases supply-chain/execution risk by (1) dot-sourcing a tool-discovery dependency that controls what binaries/args are executed and (2) auto-bootstrap via powershell.exe -ExecutionPolicy Bypass to run a bootstrap script when tools are missing. Additionally, recursive deletion under user-influenced output paths can be destructive if paths are misconfigured or manipulated. Treat as medium supply-chain risk pending verification of ToolDiscovery.ps1 and bootstrap-reverse.ps1 integrity and download/install behavior.
SUSPICIOUS. The skill is internally aligned with a database security assessment purpose, but it grants an AI agent explicit offensive security capability and routes work toward additional pentest-related modules. No clear credential-exfiltration, hidden execution, or malicious data flow is shown, and the scanner hit is likely a false positive; the main risk is the inherently high-impact security-testing scope plus some transitive-trust ambiguity.
This fragment is best characterized as an anti-analysis/sandbox-evasion guidance module rather than normal library functionality. It enumerates multiple environment fingerprinting and analysis-detection techniques (VM/firmware/hardware/process/window/registry/device artifacts) and includes example logic demonstrating behavioral suppression (e.g., terminating execution when time acceleration or analysis indicators are detected). No direct evidence of malware payload actions (network exfiltration, persistence, or system modification) is present in the fragment, but the actionable evasion mechanics and decision-to-stop pattern present a significant supply-chain risk and warrant reviewing the actual package’s executable code paths, install scripts, and runtime behavior to confirm whether these techniques are used maliciously.
High-risk and strongly indicative of malicious/offensive capability. The fragment provides explicit, multi-layer runtime bypasses for root/jailbreak detection and anti-debugging checks on Android and iOS, and most critically disables TLS certificate/pinning validation across multiple networking stacks by forcing trust decisions to succeed. If present in a software supply-chain dependency, it would materially enable stealth instrumentation and TLS MITM/credential interception workflows. Obfuscation is not evident; the danger is in direct tampering of security-critical outcomes. Additional context is needed to confirm whether this code actually executes in the package, but the described behaviors are inherently unsafe.
This fragment is highly suspicious supply-chain content because it provides weaponizable XXE exploitation logic: external DTD loading, local file reads (e.g., /etc/passwd via file:// and php://filter), and out-of-band data exfiltration to attacker infrastructure, plus SSRF/internal probing and docx XML injection techniques. While it is not runtime malware code, its inclusion significantly increases misuse potential and should be reviewed/removed or tightly isolated (e.g., defensive-only training materials with appropriate safeguards).
This artifact is high-risk and strongly indicates malicious/sabotage intent: it provides actionable instructions and examples to tamper with Unity IL2CPP Android apps by bypassing in-app purchase/receipt verification and altering monetization/economic logic via static native patching and dynamic Frida IL2CPP method hooking. No explicit network exfiltration or credential theft is demonstrated, but the described behavior is a practical integrity-bypass and unauthorized modification workflow. If distributed in a supply chain, it would meaningfully increase an attacker’s capability.
This fragment is a reverse-engineering and security-bypass guide (not a typical npm/PyPI dependency). It provides concrete Frida hook implementations that actively defeat jailbreak/sandbox, anti-injection/dyld heuristics, and anti-debug checks by altering return values and replacing system functions. While there is no evidence of cryptomining, credential theft, or network exfiltration in the snippet, the intent and mechanics strongly enable bypassing security controls, making it high-risk from a misuse perspective. Lack of a real package/dependency makes malware-within-a-package unprovable, but the security risk of the provided techniques is substantial.
This fragment is high-risk offensive automation guidance: it specifies a loop that performs recon and vulnerability detection, then proceeds to exploit/PoC verification and evidence capture, with Burp MCP replay integration and proxy-pool-based evasion to sustain scanning. While it does not itself show embedded malicious code, distributing or embedding this workflow in a software dependency/agent framework materially increases capability for unauthorized exploitation unless strict authorization and safety guardrails are enforced externally.
This artifact is highly actionable, weaponized Log4Shell exploitation material. It directly instructs how to craft JNDI payloads, verify them via OOB callbacks, stand up attacker-side LDAP/RMI/HTTP services, and achieve command execution/reverse-shell style outcomes. As a supply-chain component, it represents a serious abuse/propagation risk (even if it is not evidence of runtime malware execution).
This fragment is an end-to-end, functional ret2libc/ROP exploit template that leverages a leaked address from a remote service to compute libc base and then triggers system('/bin/sh') on the target, followed by io.interactive() to provide an interactive shell. In a supply-chain context, there is no evidence here of classic malware behaviors such as persistence or data exfiltration, but the included capability is inherently high-impact: if bundled into software that auto-runs or is executed outside the intended CTF context, it could enable remote shell access on affected systems. Treat the content as security-sensitive/offensive material rather than a benign dependency.
High misuse risk. The fragment is an explicit, actionable Active Directory compromise playbook centered on Kerberoasting/AS-REP roasting, offline password cracking, BloodHound-assisted privilege pathing, and optional high-impact post-exploitation steps (e.g., NTDS extraction and credential dumping). There is no code obfuscation; the danger comes from operational guidance that enables credential theft and escalation to Domain Admins.
The fragment contains directly reusable offensive capabilities: it provides concrete Frida logic to bypass iOS jailbreak/anti-tamper checks by falsifying NSFileManager existence results and replacing fork() to force deterministic failure behavior. It also describes enabling HTTP(S) traffic inspection by defeating SSL pinning and using trusted MITM tooling. There is no evidence of obfuscation. If distributed as a software dependency, it would materially increase an attacker’s ability to tamper with app integrity checks and intercept network traffic, indicating a high security risk despite the testing framing.
This artifact is an adversarial malware/stealth tradecraft guide. It provides actionable instructions to bypass EDR/AV and AMSI, evade ETW/telemetry, conceal payloads in memory (injection/module stomping/memory encryption), and execute/download attacker payloads via LOLBins, followed by covert C2 transport techniques. It should be treated as high-risk malicious operational content and not as a legitimate dependency or reference material for production systems.
This fragment is an offensive SSL-pinning bypass guide with actionable Frida hook code that disables OkHttp certificate pinning and Conscrypt trust-chain verification (and suggests hostname verification bypass). It is designed to enable interception of HTTPS traffic (e.g., with Burp) and discusses evasion of anti-Frida measures—indicating high misuse potential. No obfuscation is present, but the security impact is substantial.
SUSPICIOUS. The skill is internally coherent for authorized OT/ICS assessment and shows strong safety constraints, so it is not overtly malicious. However, it gives an AI agent high-risk offensive security capabilities in industrial environments and extends into other security-oriented skills, making it unsuitable as a low-risk general-purpose skill.
This module is a dual-use Frida orchestration wrapper that can enumerate devices/processes and attach/spawn to a selected package/process while loading a caller-provided Frida script. The main supply-chain/execution-integrity risks are (1) auto-bootstrap that runs a relative bootstrap PowerShell script using -ExecutionPolicy Bypass, and (2) direct loading of an external Frida script from an unvalidated path. No explicit credential theft, persistence, or network exfiltration logic is visible in this snippet; however, the capabilities and execution pivots make misuse or compromise of the bootstrap/script inputs a significant security concern.
SUSPICIOUS. The main Ghidra workflow is coherent and mostly benign for its stated purpose, but this is still a high-risk reverse-engineering skill and it tells the agent to bootstrap third-party ghidra-mcp without a pinned, same-org source. No credential theft, exfiltration, or confirmed malicious behavior is evident.
The provided artifact is not a software dependency implementation; it is an explicitly adversary-oriented intrusion playbook covering end-to-end exploitation, credential theft, lateral movement, AD/AD CS abuse, phishing, and cloud metadata/token exploitation. No executable code is present in the snippet, but its content is directly reusable for wrongdoing and represents an extreme security risk if included in or distributed with a software package.
This fragment describes a high-suspicion loader pattern: an embedded compressed payload in a disguised ARM64 ELF container, reconstructed via a custom LZSS-like decompressor and executed in-memory by mmap→mprotect(RW→RX)→jump. It also notes analysis-evasion tactics (misleading file type and intentionally corrupted ELF headers) and payload characteristics consistent with process-injection intent. Even though the actual runnable code is not included here, the described behavior is characteristic of malware droppers/loaders, making the overall security risk moderate-to-high for a dependency context.
This fragment is an offensive API exploitation/testing playbook with concrete GraphQL introspection/DoS/authorization-mutation attempts, REST injection/mass-assignment/parameter-pollution examples, and SSRF payloads targeting cloud metadata and file:// URIs. It does not itself provide evidence of dependency-level malware execution (no installation/runtime behavior shown), but it is highly dangerous as supply-chain-distributed attacker enablement material that can be used to attack real systems. Recommend treating it as high security risk if published or shipped with software, and ensuring it is not included in production artifacts or publicly distributed without clear defensive intent and access controls.
SUSPICIOUS. The stated purpose as a CTF router broadly matches the handoff behavior, and the network-gating language is safety-oriented. However, the skill still executes an unverifiable local PowerShell script immediately and delegates to a sidecar skill tree, so trust depends on unreviewed repository-local content rather than a verified release path. No direct evidence of credential theft or malicious exfiltration appears in this snippet.
This fragment is an explicit offensive Active Directory compromise procedure (NTLM relay + coercion + delegation abuse + Kerberos impersonation + domain controller secrets dumping). It contains no benign library behavior and, if present in any software package or execution path, would be directly usable for unauthorized intrusion and credential theft. No meaningful obfuscation is present, and the intent is unambiguous.
This skill is coherent with its stated purpose, but that purpose is itself a high-risk offensive security capability for an AI agent. There is no strong evidence of malware or covert exfiltration, yet the pentest focus and reliance on third-party security tools make it a high security-risk skill overall.
The provided material is an attacker-style exploitation chain describing SSRF-based cloud metadata credential harvesting (including IMDSv2 token steps) followed by full object-storage bucket enumeration and bulk export/synchronization. This indicates highly malicious intent/impact in an offensive context, but the fragment is not actual dependency source code, so it cannot definitively prove that a particular package contains malware. Treat any inclusion of similar logic/scripts in a dependency as critical to investigate.
This module primarily acts as a scheduled-task persistence installer for a local watchdog.ps1, using stealth features (hidden task and hidden PowerShell window) and weakening script execution controls (-ExecutionPolicy Bypass). It also establishes long-lived, frequent execution and restart-on-failure behavior, all of which increase supply-chain security risk. No direct exfiltration/credential theft/network activity is observable in the provided fragment; confirming or ruling out malware requires inspection of watchdog.ps1 and the processes it manages.
The reviewed fragment does not include the actual Frida script code, but it clearly describes a turnkey runtime bypass kit that can disable root/emulator/anti-debug checks and bypass TLS certificate-chain validation/SSL pinning by hooking TrustManagerImpl methods. This functionality is highly dual-use and materially increases misuse potential, especially due to the claimed certificate-validation bypass. No direct evidence of extra malware behaviors (exfiltration, persistence, etc.) is present in the fragment, but such behaviors cannot be ruled out without inspecting the real script.
The skill is coherent for reverse engineering Go/Rust binaries and does not show credential theft, exfiltration, or suspicious installer behavior. However, it grants an AI agent explicit offensive reverse-engineering and malware-analysis capability, which makes it high security risk despite low evidence of malicious intent.
SUSPICIOUS: the skill is coherent with its stated purpose, but that purpose is to enable offensive hardware security testing by an AI agent. There is no clear credential theft, exfiltration, or malicious installer behavior, yet the embedded exploitation workflow and cross-skill chaining make it high security risk overall.
SUSPICIOUS: The skill is internally coherent for browser-extension reverse engineering, but it grants an AI agent explicit offensive security/reversing capability and suggests dynamic tooling that broadens impact. No clear malware or exfiltration behavior is present, yet the capability class and transitive/tool trust issues make it high security risk.
This artifact provides highly actionable malicious capability: an end-to-end AD CS ESC1 abuse chain that escalates privileges via certificate impersonation and then performs DCSync-style credential dumping. It contains explicit operational steps, target parameters, and example credentials, with no defensive intent or benign software behavior described.