cybercentry-quantum-cryptography-verification

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's main behavior is to send plaintext, including example credentials and `.env` secrets, to a third-party paid encryption service. While remote encryption is arguably aligned with the stated purpose, the scope is disproportionate for sensitive secret handling, the data flow relies on external services and tokenized URLs, it encourages transitive trust in another skill, and it enables autonomous paid actions. This is not confirmed malware, but it is a high-risk skill for credential exposure and data exfiltration.

Confidence: 86%Severity: 83%
Audit Metadata
Analyzed At
Mar 18, 2026, 04:24 AM
Package URL
pkg:socket/skills-sh/Cybercentry%2Fcybercentry-agent-skills%2Fcybercentry-quantum-cryptography-verification%2F@0fe00647fb8cf53bf8daf0ac3429793b3ebd3eb0