Generate Nano QR Code
Warn
Audited by Socket on Mar 15, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
Purpose and requested inputs are proportionate: generating a Nano payment QR from a public address is coherent and low-scope. The main issue is install trust: the skill relies on an unpinned `npx -y xno-skills` execution path whose package provenance was not verified from the supplied evidence, making this suspicious but not clearly malicious.
Confidence: 84%Severity: 58%
Audit Metadata