moa

Warn

Audited by Socket on Jul 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose largely matches its behavior, but it materially expands data exposure by sending prompts and possibly repository contents to multiple external backends, including OpenRouter as an intermediary. The biggest concern is trust/provenance of the local ~/.claude skill script plus credential/data forwarding to third-party tooling; this is risky but not clearly malicious from the provided evidence.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Jul 8, 2026, 08:24 AM
Package URL
pkg:socket/skills-sh/dandacompany%2Fclaude-moa%2Fmoa%2F@cd3d7d29bab0053e8618f6a33d113e459e654a19a2dd57cb6944e5eb49acb5e9
Security Audit — socket — moa