recharge-skill

Warn

Audited by Socket on Sep 14, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is broadly coherent with its stated BANK OF AI recharge/query purpose and uses apparently same-org endpoints, so this is not confirmed malware. Risk is elevated because it handles account credentials and enables real-world financial recharges through a remote MCP service, which is proportionate to purpose but inherently high-impact.

Confidence: 89%Severity: 68%
AnomalyLOW
README.md

No direct malware is demonstrated in the supplied documentation. However, it specifies transmission of a BANK OF AI API key to an external recharge endpoint, creating a material credential-exposure and trust risk. The omitted scripts and SKILL.md require separate review before use.

Confidence: 98%Severity: 58%
Audit Metadata
Analyzed At
Sep 14, 2026, 10:06 PM
Package URL
pkg:socket/skills-sh/bofai%2Fskills%2Frecharge-skill%2F@f409d922ddb714c6626e583450ae34f4c4af6c5bb0b54d2f7cf1fdc1bdb28c1b
Security Audit — socket — recharge-skill