data-enrichment

Warn

Audited by Socket on Apr 19, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core purpose is coherent, but the actual footprint routes sensitive enrichment queries through a third-party gateway (`stableenrich.dev`) and a mutable external CLI (`npx agentcash@latest`) rather than official provider APIs. That combination is disproportionate for high-sensitivity personal data enrichment and creates meaningful supply-chain, privacy, and credential-forwarding risk, though it is not confirmed malware.

Confidence: 84%Severity: 74%
Audit Metadata
Analyzed At
Apr 19, 2026, 11:25 AM
Package URL
pkg:socket/skills-sh/Merit-Systems%2Fagentcash-skills%2Fdata-enrichment%2F@e2bba57714aea0d5a7f690c1edee34e9927509e9
Security Audit — socket — data-enrichment