lending

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose and capabilities are broadly aligned, but it combines mutable runtime installation of a third-party CLI (`npx ...@latest`) with autonomous high-impact financial actions. There is no clear credential theft or overt exfiltration in the skill text, but the install trust and transaction authority make it high risk.

Confidence: 85%Severity: 84%
Audit Metadata
Analyzed At
Mar 15, 2026, 04:45 PM
Package URL
pkg:socket/skills-sh/ahmetenesdur%2Fstarkfi%2Flending%2F@bccdcb3126fa4eb9f7b191f8bc0e62a3dc965dae