yuanbao

Warn

Audited by Socket on Aug 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill is purpose-aligned for Yuanbao group interaction, but it grants the agent autonomous outbound messaging and DM capability with optional file transfer, and it hides the actual gateway endpoint behind implicit delivery. There is no strong malware evidence or supply-chain abuse in the provided skill, but the real-world action surface and opaque transport path make it medium/high risk.

Confidence: 87%Severity: 72%
Audit Metadata
Analyzed At
Aug 28, 2026, 12:49 PM
Package URL
pkg:socket/skills-sh/tt-a1i%2Fhermes-agent%2Fyuanbao%2F@c37225ede6d75a92f2536f5779516eb811ce48a0cdd1b0b1888bd48225908225
Security Audit — socket — yuanbao