price-change

Warn

Audited by Socket on Mar 27, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is purpose-aligned and uses official-looking data flows, so it is not malware-like; however, it grants an AI agent broad authority to change production Stripe billing and push directly to main across multiple repos. This is a high-impact operational skill whose risk comes from autonomous real-world actions and broad write scope, not supply-chain behavior or credential theft.

Confidence: 88%Severity: 68%
Audit Metadata
Analyzed At
Mar 27, 2026, 01:04 PM
Package URL
pkg:socket/skills-sh/psquared-development%2Fpsquared-skills%2Fprice-change%2F@7dd3213c4abd5c02a39547685826ded85c3f80ce
Security Audit — socket — price-change