firmware-analyst

Fail

Audited by Socket on Mar 1, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

Overall, the skill fragment presents a coherent and legitimate framework for firmware security assessment with workflows that match the stated purpose. The primary security concern is the unverified HTTP firmware download, which could enable supply-chain tampering if integrity checks are not applied. To elevate safety, enforce TLS/HTTPS, implement and verify cryptographic signatures or checksums, and consider pinning to trusted vendor hashes. Aside from this, the data flows and permission footprint are appropriate for an authorized firmware audit context.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 1, 2026, 03:08 PM
Package URL
pkg:socket/skills-sh/sickn33%2Fantigravity-awesome-skills%2Ffirmware-analyst%2F@34df414e234756f4aa4643dd6bc7e2404d2dad39