deepsky-sustain

Warn

Audited by Socket on Mar 24, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's core purpose is coherent with Deepsky account sustain operations, but its footprint is broader and riskier than a simple monitoring skill: it authorizes autonomous top-ups, recurring job installation, wallet/provider bootstrap, and silent transitive installation of other skills from GitHub. The biggest concern is the combination of autonomous financial actions and unreviewed skill-to-skill installation, not confirmed malware.

Confidence: 87%Severity: 84%
Audit Metadata
Analyzed At
Mar 24, 2026, 06:49 AM
Package URL
pkg:socket/skills-sh/appfi5%2Fdeepsky-tools%2Fdeepsky-sustain%2F@02a9b53ef0c306499791dda4782ecd43bd81adc6