05-character-identity-onboarding
Warn
Audited by Socket on Aug 12, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s core ledger and verification workflow is coherent, and the HeyGen examples appear aligned with official APIs, but the Google Flow path routes authenticated activity through useapi.net and requires forwarding Google session cookies to a third party. That intermediary credential/data flow is the primary risk and makes the overall skill medium-high risk despite otherwise legitimate purpose alignment.
Confidence: 91%Severity: 79%
Audit Metadata