money-product
Warn
Audited by Socket on May 5, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the core build/deploy/payment capabilities generally fit the stated purpose and mostly rely on official vendors, but the skill is high-impact and unusually broad. The strongest concern is the ccapi.ai fallback, which routes Gemini-related credentials/traffic through a third-party intermediary instead of Google’s official path, plus transitive skill loading and real-world deployment/payment actions with limited explicit approval boundaries.
Confidence: 88%Severity: 74%
Audit Metadata