didit-biometric-age-estimation

Fail

Audited by Socket on Mar 3, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This skill is a documentation/specification for using Didit's age-estimation API. I found no signs of supply-chain download-execute vectors, credential harvesting to unknown third parties, obfuscated malware, or deceptive network routing. The main security considerations are expected for this domain: sensitive biometric and ID data are uploaded to the Didit service (so deployers must ensure compliance with privacy laws, secure handling of API keys and account credentials, retention policies, and TLS usage). No explicit malicious behavior is present in the supplied text, but the biometric nature of the data and absence of privacy/retention details elevate overall operational risk and require careful handling by integrators.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 3, 2026, 05:23 AM
Package URL
pkg:socket/skills-sh/didit-protocol%2Fdidit-agent-skills%2Fdidit-biometric-age-estimation%2F@1e8b84a02ea910f4eeabdaf4a90b0c3f3eb30d90