send

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill’s purpose and capabilities are aligned, but it gives an AI agent the ability to perform real financial transactions and does so through an unpinned `npx`-fetched CLI. There is no clear evidence of credential theft or covert exfiltration, but the combination of runtime third-party code execution and autonomous fund transfer makes this a high security-risk skill.

Confidence: 82%Severity: 81%
Audit Metadata
Analyzed At
Mar 15, 2026, 04:45 PM
Package URL
pkg:socket/skills-sh/ahmetenesdur%2Fstarkfi%2Fsend%2F@8a632460f4d2e955818b95f4ae86fd3a505519e9