token-guard

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The stated purpose is coherent with cost monitoring and model routing, and no explicit credential harvesting or exfiltration is shown. However, the install path relies on an unverified third-party skill/repo and the actual script code is absent, so execution trust cannot be established. Overall this is better classified as SUSPICIOUS than benign due to supply-chain and transitive-install risk, not confirmed malware.

Confidence: 82%Severity: 74%
Audit Metadata
Analyzed At
Mar 13, 2026, 07:03 AM
Package URL
pkg:socket/skills-sh/aAAaqwq%2FAGI-Super-Team%2Ftoken-guard%2F@989d404a35263eabd56241abbba5050d739fd897