conducting-mobile-app-penetration-test

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill is internally consistent with its stated purpose as a mobile app penetration-testing guide, using mostly official/common tools and no obvious credential-harvesting or covert exfiltration path. However, it grants an AI agent high-risk offensive security capabilities—bypassing biometrics, TLS pinning, root detection, runtime hooks, tampering, and API interception—so the overall risk is high even though the behavior is not deceptive or clearly malicious.

Confidence: 91%Severity: 82%
Audit Metadata
Analyzed At
Apr 9, 2026, 10:27 AM
Package URL
pkg:socket/skills-sh/mukul975%2FAnthropic-Cybersecurity-Skills%2Fconducting-mobile-app-penetration-test%2F@c16b45e713bd30fc63992f83b504846900cdbf11