finance-district
Audited by Socket on May 20, 2026
2 alerts found:
Securityx2BENIGN for its stated purpose, but high inherent operational risk: it is a commerce skill that intentionally spends money, transmits buyer PII to merchants, and uses a wallet CLI to authorize payment. The footprint is internally consistent and the install source appears same-org/official, so this is not malware-like; the main concern is the powerful financial capability and broad network reach.
The skill is purpose-aligned and appears to use an official same-org npm-distributed CLI rather than a suspicious downloader, so it is not malware by itself. However, it is high risk because it grants an AI agent the ability to authenticate accounts, manage merchant access, and execute real financial transactions, with an autonomous OTP path if inbox access is available.