crow
Warn
Audited by Socket on Mar 14, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The core Crow payment behavior is broadly aligned with the stated purpose and routes data to the claimed vendor domain, but the skill is inherently high risk because it authorizes autonomous financial transactions. Risk is increased by partial public verifiability of the API flow and by the instruction to install an unrelated third-party Nightmarket skill, creating transitive trust beyond Crow itself.
Confidence: 88%Severity: 78%
Audit Metadata