bni-121

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s core purpose is coherent, and data is routed to official BNI domains, but it is high-trust automation that collects raw credentials, extracts JWTs from browser localStorage, uses undocumented internal APIs, and has broad execution permissions. This looks more like risky account automation than confirmed malware.

Confidence: 88%Severity: 69%
Audit Metadata
Analyzed At
Apr 30, 2026, 04:40 PM
Package URL
pkg:socket/skills-sh/kevin-shu%2Fbni-submit%2Fbni-121%2F@70f01ef3ba7dfec34de2d472b0f0e03a86efb177