contract-intelligence-review

Warn

Audited by Socket on Apr 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill is broadly aligned with its stated contract-review purpose and does not show malware-like install or execution behavior. The main risk is data-flow trust: sensitive contract contents and API keys are routed to arbitrary OCR/LLM endpoints defined by environment variables, so backend legitimacy and handling cannot be verified from the skill itself.

Confidence: 83%Severity: 52%
Audit Metadata
Analyzed At
Apr 15, 2026, 05:58 AM
Package URL
pkg:socket/skills-sh/iflytek%2FiFly-Skills%2Fcontract-intelligence-review%2F@3e37ecefbe35b846cb5e0db64013f3e958e2d859
Security Audit — socket — contract-intelligence-review