use-agently

Warn

Audited by Socket on Mar 6, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The fragment presents a coherent CLI workflow for discovering and paying AI agents via Agently, but key security concerns around private key management (plaintext storage) and automated payments necessitate stronger safeguards. Improvements should include encrypted or vault-backed key storage, strict file permission handling, explicit rotation, signed and integrity-checked updates, and careful logging to prevent leakage of wallet data. The overall security posture is moderate but leans toward high risk if deployed without mitigations.

Confidence: 70%Severity: 56%
Audit Metadata
Analyzed At
Mar 6, 2026, 04:11 AM
Package URL
pkg:socket/skills-sh/agentlyhq%2Fuse-agently%2Fuse-agently%2F@2c1380bcb2c7746f4fe9bce41408ca1ba7512937