nutmeg-acquire

Warn

Audited by Socket on May 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is mostly coherent with a football-data acquisition purpose and generally routes credentials to official endpoints, but it combines broad tool permissions with untrusted external content handling and relies on third-party community packages and the Reep/withqwerty mapping service. This looks more like a high-risk data-ingestion skill than malware: acceptable if carefully sandboxed, but not low risk.

Confidence: 85%Severity: 57%
Audit Metadata
Analyzed At
May 12, 2026, 08:31 PM
Package URL
pkg:socket/skills-sh/withqwerty%2Fnutmeg%2Fnutmeg-acquire%2F@102bf72e0c6946bac8382c3b256c57bb7f2bd905