ap2-intent-mandate

Warn

Audited by Socket on Mar 31, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is not overtly malicious and its external references appear official, but it combines live web/GitHub ingestion with Write+Bash permissions and targets autonomous purchasing. The main concern is a coherence gap: it instructs implementation of a human-not-present AP2 Intent Mandate even though the public spec evidence indicates v0.1 primarily supports human-present flows. This is best classified as medium risk due to prompt-injection exposure and finance-adjacent autonomy, not credential theft or malware.

Confidence: 87%Severity: 61%
Audit Metadata
Analyzed At
Mar 31, 2026, 06:09 AM
Package URL
pkg:socket/skills-sh/OrcaQubits%2Fagentic-commerce-skills-plugins%2Fap2-intent-mandate%2F@08f04e59d2a545f368016a7de06b324b35760ca9