tempo

Warn

Audited by Socket on Jun 3, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's core behavior is mostly aligned with its stated purpose, and the installer appears same-org and officially documented, so this is not confirmed malicious. However, it combines mutable `curl|bash` installation, credential/payment mediation through an external CLI, paid API execution, optional card-provider keys, and remote file downloads, making the overall footprint medium risk and broader than a simple HTTP helper.

Confidence: 82%Severity: 64%
AnomalyLOW
.changelog/config.toml

The code fragment itself does not perform file IO, network requests, or data processing directly, but it includes a suspicious AI invocation that attempts to coerce an external AI service into producing a tightly controlled output. This represents a potential supply-chain and data-leak risk if secrets are ever included in inputs or configurations are executed in user environments. The dominant concern is the AI prompt injection-like pattern and reliance on a third-party service in a package configuration, which could enable information leakage or unintended behavior in CI/CD pipelines.

Confidence: 59%Severity: 60%
Audit Metadata
Analyzed At
Jun 3, 2026, 01:27 AM
Package URL
pkg:socket/skills-sh/tempoxyz%2Fwallet%2Ftempo%2F@8732a31a910feae054655a84a887710d5b1a28b7
Security Audit — socket — tempo