cybercentry-quantum-cryptography-verification
Warn
Audited by Socket on Mar 18, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill's main behavior is to send plaintext, including example credentials and `.env` secrets, to a third-party paid encryption service. While remote encryption is arguably aligned with the stated purpose, the scope is disproportionate for sensitive secret handling, the data flow relies on external services and tokenized URLs, it encourages transitive trust in another skill, and it enables autonomous paid actions. This is not confirmed malware, but it is a high-risk skill for credential exposure and data exfiltration.
Confidence: 86%Severity: 83%
Audit Metadata