mobile-monetization

Warn

Audited by Socket on Mar 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core monetization-audit purpose is coherent with codebase scanning, and I found no explicit credential harvesting or external exfiltration. Risk comes from autonomous behavior without user clarification, nonessential telemetry writes into hidden Claude memory, and transitive trust introduced by recommending other slash commands. This looks like a broadly scoped local analysis skill with moderate security risk, not confirmed malware.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
Mar 23, 2026, 11:03 AM
Package URL
pkg:socket/skills-sh/tinh2%2Fskills-hub-registry%2Fmobile-monetization%2F@b8ff875641e06ea8381b07bf0929ff6b3b0dc5bb
Security Audit — socket — mobile-monetization