antom-integration

Warn

Audited by Socket on May 6, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s stated purpose is legitimate and payment-related guidance is broadly aligned, but it depends on dynamic remote documentation fetched via curl from partly unverifiable endpoints outside the main Antom docs domain. There is no clear credential theft or malicious exfiltration, yet the remote-content dependency and recursive doc ingestion create medium supply-chain and prompt-injection risk.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
May 6, 2026, 07:41 AM
Package URL
pkg:socket/skills-sh/ant-intl%2Fantom-ai-tools%2Fantom-integration%2F@b7e636e9e66f01cb4e0d5ae9a66065e7816a715f