oneshot-enrichment

Warn

Audited by Socket on Jun 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core capability matches the stated enrichment purpose and the SDK/source relationship appears legitimate, but the skill introduces wallet-backed paid actions, secret forwarding into an SDK, sensitive personal-data processing, and transitive trust on another skill. Data flows appear same-brand rather than overtly exfiltrative, so this is not confirmed malware, but it is higher-risk than a normal read-only lookup skill.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Jun 18, 2026, 04:25 PM
Package URL
pkg:socket/skills-sh/oneshot-agent%2Fagent-skills%2Foneshot-enrichment%2F@38dc6b9225f3f75e651908c8f78d0c5b92093a649eefd7b28514115ce474eb82
Security Audit — socket — oneshot-enrichment