money-product

Warn

Audited by Socket on May 5, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core build/deploy/payment capabilities generally fit the stated purpose and mostly rely on official vendors, but the skill is high-impact and unusually broad. The strongest concern is the ccapi.ai fallback, which routes Gemini-related credentials/traffic through a third-party intermediary instead of Google’s official path, plus transitive skill loading and real-world deployment/payment actions with limited explicit approval boundaries.

Confidence: 88%Severity: 74%
Audit Metadata
Analyzed At
May 5, 2026, 05:48 PM
Package URL
pkg:socket/skills-sh/iamzifei%2Fshow-me-the-money%2Fmoney-product%2F@d1c84c76a0d63a6f247fca139b306a792db6b05d