colosseum-copilot

Warn

Audited by Socket on Apr 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: core Colosseum API use is coherent and mostly benign, but the skill stores the user's PAT locally and includes a configurable telemetry exfiltration path via convexUrl with consent sequencing that is internally inconsistent. Not confirmed malware, but it has meaningful privacy and credential-handling risk.

Confidence: 85%Severity: 58%
Audit Metadata
Analyzed At
Apr 14, 2026, 03:28 PM
Package URL
pkg:socket/skills-sh/sendaifun%2Fsolana-new%2Fcolosseum-copilot%2F@9ab6793cb1856faa982cdae42a29ae423afc7876