cookiy

Warn

Audited by Socket on Mar 17, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
skills/cookiy/SKILL.md

SUSPICIOUS: the skill's purpose broadly matches its capabilities, but it expands the agent with externally installed MCP tooling, OAuth-backed remote control flow, and real-world recruitment/payment actions. The main concerns are supply-chain trust, sensitive data leaving to a hosted service, and server-directed agent behavior rather than obvious malware indicators.

Confidence: 78%Severity: 69%
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose broadly matches its capabilities, but it expands the agent with externally installed MCP tooling, OAuth-backed remote control flow, and real-world recruitment/payment actions. The main concerns are supply-chain trust, sensitive data leaving to a hosted service, and server-directed agent behavior rather than obvious malware indicators.

Confidence: 78%Severity: 69%
Audit Metadata
Analyzed At
Mar 17, 2026, 09:17 AM
Package URL
pkg:socket/skills-sh/cookiy-ai%2Fcookiy-skill%2Fcookiy%2F@4df2609e6254b5bbeb25e2ca5376e3d62be0d87a