nextpay
Warn
Audited by Socket on Mar 31, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the business-management purpose is coherent, but the trust model is not. The skill chains into another skill install and then installs an unverifiable CLI via pipe-to-shell; that CLI receives authentication input and stores session credentials locally while enabling privileged account actions. This is a high supply-chain and credential-forwarding risk even without proof of malicious intent.
Confidence: 88%Severity: 84%
Audit Metadata