starchild-auth
Warn
Audited by Socket on Aug 21, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The endpoints and main data flows are coherent with official Starchild services, so this does not look like credential harvesting malware. However, the skill’s actual footprint is much broader than its auth-focused name and description: it grants an AI agent access to payments, wallets, private-key export, containers, terminal sessions, and other high-impact operations. That scope is disproportionate for an auth SDK guide and creates high operational risk even without clear malicious intent.
Confidence: 85%Severity: 76%
Audit Metadata