getting-started

Warn

Audited by Socket on Apr 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose is plausible, but the actual data flow is inconsistent with official Recoupable documentation: credentials and API traffic are routed through an undocumented Vercel host, and the skill advertises an unverified self-service agent signup path that can mint API keys automatically. The npm install alone is not decisive, but combined with the endpoint mismatch and autonomous credential issuance, the skill’s footprint is not proportionate to normal onboarding.

Confidence: 90%Severity: 84%
Audit Metadata
Analyzed At
Apr 14, 2026, 03:05 AM
Package URL
pkg:socket/skills-sh/recoupable%2Fskills%2Fgetting-started%2F@33d8c5b18ed43f4187485e95881c2f56763dd3b1
Security Audit — socket — getting-started