oauth-helper
Warn
Audited by Socket on Sep 2, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill's purpose matches browser OAuth automation, but its footprint is high-risk: it uses pre-logged identity-provider sessions, can authorize third-party site access, and routes sensitive auth context and possibly screenshots/QR codes through Telegram. There is no clear malware payload or installer abuse, but the data flow and real-world account actions are disproportionate enough to treat it as a high-risk vulnerable skill.
Confidence: 88%Severity: 81%
Audit Metadata