gate-exchange-affiliate

Warn

Audited by Socket on Mar 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The business purpose and API scope are mostly coherent for an affiliate-reporting skill, and there is no clear exfiltration or malicious automation. However, the core install path is inconsistent with Gate’s documented MCP setup: the skill tells the agent to install an unverified `gate-mcp` package, while official Gate docs reference a hosted MCP endpoint and a different client workflow. Because authenticated partner data would flow through external tooling of unclear provenance, the skill carries high supply-chain and credential-forwarding risk despite an otherwise plausible purpose.

Confidence: 87%Severity: 81%
Audit Metadata
Analyzed At
Mar 16, 2026, 03:20 AM
Package URL
pkg:socket/skills-sh/gate%2Fgate-skills%2Fgate-exchange-affiliate%2F@13903096e9fb583c47f9ba81854cd552e77caeed