navvi-signup

Warn

Audited by Socket on Apr 14, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
playbooks/outlook.md

This fragment is a browser-automation playbook that enables automated Microsoft account signup, including explicit CAPTCHA-handling (press-and-hold) and a human/special intervention fallback to proceed. While there are no classic malware indicators in the provided text (no persistence, exfiltration, or host compromise mechanisms), it substantially increases capability for automated account provisioning/botting and thus presents a moderate-to-high security risk in misuse scenarios.

Confidence: 66%Severity: 62%
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is purpose-aligned but high-impact. Its footprint matches account-signup automation, yet it enables autonomous external account creation, CAPTCHA handling, credential generation/storage, and persistent persona logging. Install provenance for Navvi appears same-project and official enough to avoid a malware judgment, but the mutable remote install methods and sensitive browser/credential operations make the skill high security risk.

Confidence: 88%Severity: 74%
Audit Metadata
Analyzed At
Apr 14, 2026, 12:38 AM
Package URL
pkg:socket/skills-sh/fellowship-dev%2Fnavvi%2Fnavvi-signup%2F@506f15be19badc900617923ba54acc48a911c357
Security Audit — socket — navvi-signup