symmetric-cipher-attacks

Warn

Audited by Socket on Sep 15, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md

The skill is internally consistent and does not show malware traits, credential harvesting, covert exfiltration, or suspicious installer behavior. However, it is a high-risk AI-agent skill because its stated purpose is to teach and enable offensive cryptographic exploitation workflows; the main risk is capability misuse, not deception or hidden behavior.

Confidence: 94%Severity: 74%
AnomalyLOW
BLOCK_CIPHER_ATTACKS.md

No direct evidence of supply-chain malware (no exfiltration, backdoor/persistence, credential theft, or obfuscated runtime payloads) is present in this fragment. The security concern is dual-use misuse: it provides implementable guidance for breaking/enumerating weaknesses in common cryptographic constructions (padding oracles, malleability via CBC bit-flipping, ECB oracle attacks, PRNG state cloning, and GCM nonce-reuse exploitation). If distributed as a dependency, its main impact is enabling attackers to exploit vulnerable implementations rather than performing malicious actions itself.

Confidence: 66%Severity: 55%
Audit Metadata
Analyzed At
Sep 15, 2026, 02:14 PM
Package URL
pkg:socket/skills-sh/yaklang%2Fhack-skills%2Fsymmetric-cipher-attacks%2F@40be30b3732a412be9127744ceedc645b24d3e01950d0328dea227579ebc903f
Security Audit — socket — symmetric-cipher-attacks