lucid-agent-creator

Warn

Audited by Socket on Mar 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill is primarily documentation for creating hosted Lucid agents and contains legitimate, expected capabilities: creating agents, configuring JS handlers, and performing payment-authenticated creation flows. It does not contain direct malware or obfuscated payloads. However, there are notable security risks: examples encourage handling raw private keys in code, payment signatures and wallet-derived artifacts are forwarded to platform endpoints, and handler network configuration can allow arbitrary outbound requests (including '*' wildcard) enabling potential data exfiltration. The presence of hardcoded third-party endpoints centralizes trust and increases impact if those endpoints are compromised. Overall this is not confirmed malicious, but it is a medium-risk skill that requires careful operational security (avoid embedding private keys, restrict allowedHosts, verify platform endpoints and signature verification practices).

Confidence: 80%Severity: 75%
Audit Metadata
Analyzed At
Mar 4, 2026, 10:44 AM
Package URL
pkg:socket/skills-sh/daydreamsai%2Fskills-market%2Flucid-agent-creator%2F@a076892c957903e3030bbde9ec441f353a4c37d0