ios-pentesting-tricks

Fail

Audited by Socket on Apr 9, 2026

2 alerts found:

SecurityMalware
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s footprint matches its stated purpose, but that purpose is offensive mobile security for AI agents. It is not clearly malware or credential harvesting, yet it materially increases attack capability, includes sensitive data extraction and bypass techniques, and expands scope by recommending other pentest skills.

Confidence: 92%Severity: 88%
MalwareHIGH
IOS_RUNTIME_TRICKS.md

This module is high-risk and strongly indicative of malicious/offensive capability: it provides ready-to-deploy Frida/Objection recipes to bypass jailbreak detection and TLS/SSL pinning by overwriting security decision return values, and it implements a Keychain dumper that extracts and logs secret payloads. It also includes templates for authentication/validation bypass and token manipulation. If supplied as a dependency, it would materially increase the attacker’s ability to compromise apps and steal secrets.

Confidence: 90%Severity: 90%
Audit Metadata
Analyzed At
Apr 9, 2026, 01:14 PM
Package URL
pkg:socket/skills-sh/yaklang%2Fhack-skills%2Fios-pentesting-tricks%2F@a3de32701edf550315b337e344ca078aa136a198