phantom-frida
Audited by Socket on Apr 8, 2026
2 alerts found:
SecurityMalwareSUSPICIOUS. The skill’s purpose is internally coherent, but that purpose is to automate creation of stealthy anti-detection Frida tooling for deployment on Android devices. This is high-risk offensive capability for an AI agent, with additional supply-chain risk from executing third-party build scripts and dependencies.
This fragment documents a stealth-focused, monitoring-evasive Frida-like instrumentation component, including explicit integrity-check bypass and multi-vector anti-detection measures (identifier renaming, behavioral signature alteration, timing/stack/exception manipulation, and “extended mode” string cleaning). While no implementation code is present in the excerpt to confirm how it is executed, the intent and specificity of described techniques make this a high-suspicion supply-chain item requiring strong vetting and likely deny-by-default handling in security-sensitive environments.