soul-markets

Warn

Audited by Socket on Jun 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is broadly coherent with an agent-commerce marketplace and uses vendor-matching APIs, so it does not look like disguised malware or a supply-chain lure. Risk comes from high-value credential handling, optional raw private keys, monetized autonomous actions, and guidance that could lead users to upload sensitive access details in soul.md.

Confidence: 85%Severity: 67%
Audit Metadata
Analyzed At
Jun 18, 2026, 04:27 PM
Package URL
pkg:socket/skills-sh/oneshot-agent%2Fagent-skills%2Fsoul-markets%2F@84db762adb0cf20040ae0aff94fcc8432459a1ec7ed4c4c09eb370f5257d6e3c
Security Audit — socket — soul-markets