lobstercash

Warn

Audited by Socket on May 6, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is purpose-aligned and uses a plausible official npm package, but it grants an AI agent broad payment and transaction powers with browser automation and external web/API interaction. The main risk is not hidden malware evidence; it is high-impact financial autonomy, sensitive data handling, and delegation of payment actions to an external CLI.

Confidence: 87%Severity: 82%
Audit Metadata
Analyzed At
May 6, 2026, 02:44 AM
Package URL
pkg:socket/skills-sh/Crossmint%2Flobstercash-cli-skills%2Flobstercash%2F@cee8af70f4d4447f5fbb94b82b6300cff3e84de3