sp3nd
Warn
Audited by Socket on Sep 17, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s data flows are mostly consistent with its shopping purpose and there is no clear malware or credential-exfiltration pattern, but it grants an AI agent the ability to autonomously spend crypto on real-world goods and submit irreversible on-chain payments. Combined with stored API secrets, PII handling, and unpinned blockchain dependencies, this makes the skill high risk even though the install path is relatively standard.
Confidence: 86%Severity: 78%
Audit Metadata