Generate Nano QR Code

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

Purpose and requested inputs are proportionate: generating a Nano payment QR from a public address is coherent and low-scope. The main issue is install trust: the skill relies on an unpinned `npx -y xno-skills` execution path whose package provenance was not verified from the supplied evidence, making this suspicious but not clearly malicious.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Mar 15, 2026, 08:59 AM
Package URL
pkg:socket/skills-sh/casualsecurityinc%2Fxno-skills%2Fgenerate-nano-qr-code%2F@9838f58514a4d665fa66fe9f03fa02a0251eed9e