crow

Warn

Audited by Socket on Mar 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core Crow payment behavior is broadly aligned with the stated purpose and routes data to the claimed vendor domain, but the skill is inherently high risk because it authorizes autonomous financial transactions. Risk is increased by partial public verifiability of the API flow and by the instruction to install an unrelated third-party Nightmarket skill, creating transitive trust beyond Crow itself.

Confidence: 88%Severity: 78%
Audit Metadata
Analyzed At
Mar 14, 2026, 06:34 PM
Package URL
pkg:socket/skills-sh/fallomai%2Fskills%2Fcrow%2F@6b52b0bb5e83ed3bde2b79b42d2e9005c6d96f4e