pua

Warn

Audited by Socket on Sep 11, 2026

1 alert found:

Security
SecurityMEDIUM
references/platform.md

The fragment describes a remote-connected PUA feature with silent usage tracking, authenticated API calls, payment processing, local state changes, and runtime installation of a Python dependency. It does not itself show an explicit malware payload, but it creates meaningful privacy, credential exposure, payment, and supply-chain risks. The third-party endpoint and token handling require independent verification before use; telemetry should require explicit consent and the payment and installation flows should be removed or hardened.

Confidence: 95%Severity: 72%
Audit Metadata
Analyzed At
Sep 11, 2026, 03:44 PM
Package URL
pkg:socket/skills-sh/chaitin%2Fmonkeycodeofficialplugins%2Fpua%2F@24561bd64ece3cae3d38d03ef39e070a0ab4bc9e468b02c34ebc7209a0baced3
Security Audit — socket — pua