bni-121
Warn
Audited by Socket on Apr 30, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill’s core purpose is coherent, and data is routed to official BNI domains, but it is high-trust automation that collects raw credentials, extracts JWTs from browser localStorage, uses undocumented internal APIs, and has broad execution permissions. This looks more like risky account automation than confirmed malware.
Confidence: 88%Severity: 69%
Audit Metadata