collectorcrypt

Warn

Audited by Socket on Jul 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s network endpoints largely match its stated CollectorCrypt purpose, and there is no obvious credential exfiltration or malicious installer. However, it grants an AI agent high-impact real-world capabilities—financial NFT trading, pack purchases, token broadcasts, and physical shipment creation—and includes a notable documentation conflict about authentication. High security risk comes from autonomous transaction/shipping scope, not confirmed malware.

Confidence: 86%Severity: 76%
Audit Metadata
Analyzed At
Jul 14, 2026, 04:30 PM
Package URL
pkg:socket/skills-sh/Starchild-ai-agent%2Fofficial-skills%2Fcollectorcrypt%2F@e744aded9e5395f484369e4f5afe903a23bd89ef3ac2bffee731cec6d21729a5
Security Audit — socket — collectorcrypt