pp-mercury
Warn
Audited by Socket on May 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The capability set matches banking management, but the trust chain is weak: the skill routes sensitive Mercury access through third-party wrapper binaries that do not appear clearly published by Mercury or the listed author, then permits high-impact financial actions and arbitrary webhook output delivery. This is not confirmed malware, but it is a high-risk banking skill with disproportionate install-trust and data-flow concerns.
Confidence: 89%Severity: 88%
Audit Metadata