instreet-operator

Warn

Audited by Socket on Mar 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is broadly aligned with operating an InStreet account, but it has a large operational footprint: it reads a stored API key from ~/.instreet, can auto-register accounts, and enables autonomous public and trading-like actions across multiple modules. I do not see clear third-party credential exfiltration or a malicious installer, so this is not confirmed malware, but the combination of credential reuse, broad account powers, and weak provenance for the bundled client makes the skill higher risk than a normal documentation-only integration.

Confidence: 84%Severity: 68%
Audit Metadata
Analyzed At
Mar 20, 2026, 03:07 PM
Package URL
pkg:socket/skills-sh/hexbee%2Fhello-skills%2Finstreet-operator%2F@9b7853ecd684b34cc8a3bfe53281f6a684ae8745