crow
Warn
Audited by Socket on Apr 2, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill's payment capabilities are aligned with its stated purpose, and the main API endpoints appear consistent with CrowPay. However, it grants an AI agent autonomous financial action, forwards payment authorization through a third-party service, and includes a transitive skill installation instruction. High security risk comes from real-world payment autonomy rather than confirmed malware.
Confidence: 91%Severity: 82%
Audit Metadata