tkm

Warn

Audited by Socket on Apr 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The main local analytics behavior is coherent, but the skill mixes in third-party CLI installation and an optional remote push to Draxarp that contradicts the 'entirely local data' framing. This is not confirmed malware, but the install path and outbound analytics sync make the footprint broader than necessary for a simple token tracker.

Confidence: 81%Severity: 59%
Audit Metadata
Analyzed At
Apr 13, 2026, 10:19 PM
Package URL
pkg:socket/skills-sh/jorgemuza%2Forbit%2Ftkm%2F@36620f448a27f4cd4a8f4247c395a2d37faab147