recharge-skill
Warn
Audited by Socket on Sep 14, 2026
2 alerts found:
Anomalyx2AnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill is broadly coherent with its stated BANK OF AI recharge/query purpose and uses apparently same-org endpoints, so this is not confirmed malware. Risk is elevated because it handles account credentials and enables real-world financial recharges through a remote MCP service, which is proportionate to purpose but inherently high-impact.
Confidence: 89%Severity: 68%
AnomalyREADME.md
LOWAnomalyLOW
README.md
No direct malware is demonstrated in the supplied documentation. However, it specifies transmission of a BANK OF AI API key to an external recharge endpoint, creating a material credential-exposure and trust risk. The omitted scripts and SKILL.md require separate review before use.
Confidence: 98%Severity: 58%
Audit Metadata