metengine-data-agent

Warn

Audited by Socket on Mar 27, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core functionality matches the stated purpose of paid analytics access, and the main dependency (`mppx`) appears to be a legitimate public npm CLI rather than an unverifiable binary. However, the skill authorizes real USDC spending through an external CLI and remote payment flow, with no per-request approval safeguard and reduced transparency due to anti-discovery instructions. This is high security risk for autonomous agents, but not confirmed malware.

Confidence: 86%Severity: 76%
SecurityMEDIUM
public/metengine-mpp/SKILL.md

SUSPICIOUS. The skill is broadly coherent with its stated crypto-analytics purpose, but it authorizes an AI agent to create/fund a wallet and spend real USDC on requests via an external CLI. That makes it high risk from an autonomy and financial-action perspective even without clear evidence of malware or deceptive exfiltration.

Confidence: 84%Severity: 78%
Audit Metadata
Analyzed At
Mar 27, 2026, 08:05 AM
Package URL
pkg:socket/skills-sh/MetEngine%2Fskills%2Fmetengine-data-agent%2F@a1f3589a27b4fa398fe52ea1eaf26301e1320e76