inbox
Warn
Audited by Socket on May 5, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The skill is purpose-aligned and uses project-consistent endpoints, so it does not look like credential theft or covert exfiltration. However, it gives an AI agent the ability to read untrusted inbound content and perform paid wallet-backed outbound messaging, creating high real-world action risk and moderate prompt-injection exposure.
Confidence: 86%Severity: 74%
Audit Metadata