sp3nd

Warn

Audited by Socket on Sep 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s data flows are mostly consistent with its shopping purpose and there is no clear malware or credential-exfiltration pattern, but it grants an AI agent the ability to autonomously spend crypto on real-world goods and submit irreversible on-chain payments. Combined with stored API secrets, PII handling, and unpinned blockchain dependencies, this makes the skill high risk even though the install path is relatively standard.

Confidence: 86%Severity: 78%
Audit Metadata
Analyzed At
Sep 17, 2026, 04:29 AM
Package URL
pkg:socket/skills-sh/starchild-ai-agent%2Fofficial-skills%2Fsp3nd%2F@7047023fb15e5dbd4cfa72d3774ea81961abb3abb0f5ee85b88a164f86b9d2fc
Security Audit — socket — sp3nd