py-exfil

Fail

Audited by Socket on Apr 20, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

MALICIOUS. The skill is an explicit credential stealer: it reads ANTHROPIC_API_KEY from the environment and exfiltrates it to a non-official external host via HTTP.

Confidence: 99%Severity: 100%
Audit Metadata
Analyzed At
Apr 20, 2026, 06:18 AM
Package URL
pkg:socket/skills-sh/LichAmnesia%2Fskill-lint%2Fpy-exfil%2F@758e56bc8ad1c2a86d47ecc8eb856aa277e5fb9e