sp3nd

Warn

Audited by Socket on May 6, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill’s capabilities mostly match its shopping/payment purpose, and installs come from standard sources, but it grants an AI agent high-impact autonomous purchasing and crypto payment abilities while handling PII and API secrets. The main concern is not hidden malware behavior but the inherent risk and trust required for autonomous real-world spending through a third-party commerce backend.

Confidence: 90%Severity: 81%
Audit Metadata
Analyzed At
May 6, 2026, 01:13 PM
Package URL
pkg:socket/skills-sh/Starchild-ai-agent%2Fofficial-skills%2Fsp3nd%2F@cbd4c23d56884864016cd6c436adc62d7607603f