nextpay

Warn

Audited by Socket on Mar 30, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill’s purpose and requested operations are broadly coherent, but it depends on a remotely installed, insufficiently verifiable CLI that handles authentication and stores session credentials locally. The same-brand domain reduces concern somewhat, yet the pipe-to-shell installer, black-box credential handling, and transitive skill installation make this a high security-risk skill rather than clearly benign.

Confidence: 87%Severity: 84%
Audit Metadata
Analyzed At
Mar 30, 2026, 09:45 AM
Package URL
pkg:socket/skills-sh/nextpay-ai%2Fagent-skills%2Fnextpay%2F@e79ab3a6fabab2f2361cfd939917c51b4136e522
Security Audit — socket — nextpay