mobile-ssl-pinning-bypass

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill. The content is internally consistent with offensive mobile pentesting, but it equips an AI agent with exploit-style SSL-pinning-bypass techniques, binary patching, and trust-store tampering. Install guidance is partly official for Frida/Objection, but it also brings in third-party offensive tooling and references other skills, raising transitive trust and supply-chain risk. Not confirmed malware, but inappropriate for general-purpose agents and high risk by capability.

Confidence: 91%Severity: 86%
Audit Metadata
Analyzed At
Sep 15, 2026, 07:42 AM
Package URL
pkg:socket/skills-sh/yaklang%2Fhack-skills%2Fmobile-ssl-pinning-bypass%2F@50d31286fe58b950be128509206c3852844bf73d8196415a48fb6d7413d3472a
Security Audit — socket — mobile-ssl-pinning-bypass