agent-card

Warn

Audited by Socket on Mar 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill’s capabilities largely match its stated payment-card purpose, but it grants an AI agent high-impact financial actions and access to full card credentials. No clear malicious installer or unrelated credential harvesting is present, yet the opaque MCP backend and real-world payment effects make the overall risk high.

Confidence: 83%Severity: 74%
Audit Metadata
Analyzed At
Mar 14, 2026, 01:39 AM
Package URL
pkg:socket/skills-sh/agent-cards%2Fskill%2Fagent-card%2F@15efbac76a04ed14146aa79b8b885e79b48cfbf3