ic-rooms

Warn

Audited by Socket on Jul 19, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core skill is mostly coherent and uses official Immersive Commons APIs, but the advanced/live path materially expands trust by directing users to a personal GitHub repo that receives IC credentials and mints additional room credentials. That third-party credential-forwarding step is disproportionate to the basic room-management purpose and pushes the overall risk to medium-high even without clear evidence of malware.

Confidence: 88%Severity: 72%
Audit Metadata
Analyzed At
Jul 19, 2026, 10:22 PM
Package URL
pkg:socket/skills-sh/immersive-commons%2Fic-skills%2Fic-rooms%2F@77b087b032846a7318d4068facf565096bbe4c0fb27ceb45f49471133a48d765
Security Audit — socket — ic-rooms