leapcat-kyc

Warn

Audited by Socket on Mar 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the workflow is plausibly aligned with KYC, but the trust model is weak because it relies on an unverified external CLI to handle identity documents, personal data, and authenticated submission. The main concern is not the KYC purpose itself, but the unverifiable binary and opaque data path for sensitive information.

Confidence: 84%Severity: 82%
Audit Metadata
Analyzed At
Mar 31, 2026, 11:35 PM
Package URL
pkg:socket/skills-sh/leapcat-ai%2Fleapcat-skills%2Fleapcat-kyc%2F@5d81a46c624263ffdb701fec2ed52e36de94886e
Security Audit — socket — leapcat-kyc