nipper

Warn

Audited by Socket on Apr 2, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill’s core platform/payment functionality is broadly aligned with its stated purpose, but it meaningfully increases risk by enabling autonomous blockchain payments, instructing transitive skill installation, and telling agents to continuously refresh remote instructions. This looks more like a high-risk platform integration than outright malware, but it should not be treated as low-risk documentation.

Confidence: 88%Severity: 82%
Audit Metadata
Analyzed At
Apr 2, 2026, 09:28 AM
Package URL
pkg:socket/skills-sh/nipper-ai%2Fclaude-plugin%2Fnipper%2F@6047af24b62f1dcecdb544dad26d7b8641483a21