mobile-monetization
Warn
Audited by Socket on Mar 23, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core monetization-audit purpose is coherent with codebase scanning, and I found no explicit credential harvesting or external exfiltration. Risk comes from autonomous behavior without user clarification, nonessential telemetry writes into hidden Claude memory, and transitive trust introduced by recommending other slash commands. This looks like a broadly scoped local analysis skill with moderate security risk, not confirmed malware.
Confidence: 86%Severity: 56%
Audit Metadata