treasures

Warn

Audited by Socket on Sep 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core Treasures API usage matches the stated finance purpose, but the skill materially increases risk by instructing transitive skill installation and by using a separate VPN skill to bypass geo-fenced trade endpoints. This is not confirmed malware, yet the combination of financial execution, repo-based installs, and third-party proxy routing makes the skill high risk.

Confidence: 86%Severity: 81%
Audit Metadata
Analyzed At
Sep 17, 2026, 04:30 AM
Package URL
pkg:socket/skills-sh/starchild-ai-agent%2Fofficial-skills%2Ftreasures%2F@6063cf67ce018e3b2a974cb0e918b4d62b8f7a6f23bae851354ebadf6c3431bd
Security Audit — socket — treasures