phantom-frida

Fail

Audited by Socket on Apr 8, 2026

2 alerts found:

SecurityMalware
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s purpose is internally coherent, but that purpose is to automate creation of stealthy anti-detection Frida tooling for deployment on Android devices. This is high-risk offensive capability for an AI agent, with additional supply-chain risk from executing third-party build scripts and dependencies.

Confidence: 90%Severity: 88%
MalwareHIGH
references/phantom-frida-details.md

This fragment documents a stealth-focused, monitoring-evasive Frida-like instrumentation component, including explicit integrity-check bypass and multi-vector anti-detection measures (identifier renaming, behavioral signature alteration, timing/stack/exception manipulation, and “extended mode” string cleaning). While no implementation code is present in the excerpt to confirm how it is executed, the intent and specificity of described techniques make this a high-suspicion supply-chain item requiring strong vetting and likely deny-by-default handling in security-sensitive environments.

Confidence: 70%Severity: 70%
Audit Metadata
Analyzed At
Apr 8, 2026, 04:23 PM
Package URL
pkg:socket/skills-sh/killvxk%2Ffrida-pp%2Fphantom-frida%2F@13e2ebe3f7f9c6d631b93e19e537eb089b00cac8