starling
Warn
Audited by Socket on Sep 2, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated purpose matches bank querying, but the skill’s trust model is weak: it reads a local 1Password service-account token file and forwards multiple Starling banking tokens to a small third-party CLI with limited provenance. That combination is disproportionate for a read-only finance skill and creates significant credential-handling and supply-chain risk, though it is not confirmed malware.
Confidence: 89%Severity: 78%
Audit Metadata