recharge-skill
Warn
Audited by Socket on Apr 22, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s purpose mostly matches its capabilities, but it enables financial actions and routes recharge operations through a remote MCP endpoint whose exact provenance and handling guarantees are not independently verified from the supplied evidence. Local API-key use is expected for balance/orders, yet the split local/remote model and configurable base_url make data-flow trust weaker than a fully direct official API integration.
Confidence: 79%Severity: 67%
Audit Metadata