cryptorefills-buy

Warn

Audited by Socket on Apr 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill is purpose-aligned and uses an official same-org API with no extra credentials or binary installs, so there is little sign of malware or credential harvesting. However, it enables crypto-funded purchases of digital goods, which are irreversible real-world transactions; that makes it a high security-risk skill even with explicit confirmation safeguards.

Confidence: 88%Severity: 72%
Audit Metadata
Analyzed At
Apr 16, 2026, 09:12 AM
Package URL
pkg:socket/skills-sh/cryptorefills%2Fagents%2Fcryptorefills-buy%2F@5e3cfdfcedfb5deb44b83a5af57d15d01d8c931b