didit-kyc-onboarding

Fail

Audited by Socket on Mar 3, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This skill is documentation and example integration code for Didit's KYC API. There is no embedded malicious code, remote-execute instructions, or unexpected third-party intermediary domains. The primary risks are operational and privacy-related: the integration sends highly sensitive PII and biometrics to Didit's services and requires protecting the DIDIT_API_KEY and any callback URLs. Ensure secure storage of API keys, validate and harden webhook URLs, follow data retention/encryption/compliance policies, and audit Didit's privacy/security posture before sending production data. No signs of obfuscation or active malicious behavior were found.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 3, 2026, 05:23 AM
Package URL
pkg:socket/skills-sh/didit-protocol%2Fdidit-agent-skills%2Fdidit-kyc-onboarding%2F@19c877b3d46ae7575339d42e18f5f0288cd8308e