didit-database-validation

Fail

Audited by Socket on Mar 11, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The skill is conceptually aligned with its stated purpose of validating identities via the Didit database. Data is transmitted to official Didit endpoints using a provided API key and user-provided identity data. The main concerns are around data privacy, retention, and user consent, as well as ensuring secure handling of PII and avoidance of unnecessary logging of sensitive data. No evidence of unsanctioned credential forwarding or malware behavior is present. Overall, the footprint is coherent with its purpose but warrants explicit privacy/compliance controls and robust secret-management practices to be considered safe for production use.

Confidence: 98%Severity: 55%
Audit Metadata
Analyzed At
Mar 11, 2026, 06:45 AM
Package URL
pkg:socket/skills-sh/didit-protocol%2Fskills%2Fdidit-database-validation%2F@d35a074eb9ee247916ae62c82ea18417562ecd3e