inbox

Warn

Audited by Socket on May 5, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill is purpose-aligned and uses project-consistent endpoints, so it does not look like credential theft or covert exfiltration. However, it gives an AI agent the ability to read untrusted inbound content and perform paid wallet-backed outbound messaging, creating high real-world action risk and moderate prompt-injection exposure.

Confidence: 86%Severity: 74%
Audit Metadata
Analyzed At
May 5, 2026, 02:42 AM
Package URL
pkg:socket/skills-sh/aibtcdev%2Fskills%2Finbox%2F@d54bd2c9e7a86cdde5b59496471ff5f4308247bf
Security Audit — socket — inbox