nightmarket

Warn

Audited by Socket on Mar 10, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The Nightmarket skill presents a coherent vision of finding and paying for third-party APIs via CrowPay, but its footprint is incongruent with a benign helper. The installation method from GitHub, credential handling (stored API key), and automated on-chain payment workflow create elevated risk due to supply-chain, credential exposure, and financial flow complexities. This combination warrants a SUSPICIOUS classification, with security risk elevated by the unverifiable binary installations and credential-forwarding patterns. Mitigations would include pinning and verifying all dependencies from official registries, eliminating transitive skill installations, introducing explicit user consent for each paid call, and robust secret management plus auditable payment controls.

Confidence: 72%Severity: 78%
Audit Metadata
Analyzed At
Mar 10, 2026, 08:33 PM
Package URL
pkg:socket/skills-sh/Fallomai%2Fskills%2Fnightmarket%2F@2d3bf4f6a11857530c461e0379e28e9c273d8a54