lending
Warn
Audited by Socket on Mar 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s purpose and capabilities are broadly aligned, but it combines mutable runtime installation of a third-party CLI (`npx ...@latest`) with autonomous high-impact financial actions. There is no clear credential theft or overt exfiltration in the skill text, but the install trust and transaction authority make it high risk.
Confidence: 85%Severity: 84%
Audit Metadata