agentcash

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's broad hosted-service marketplace is mostly aligned with its stated purpose, but it relies on an unpinned external CLI, routes data through many third-party service domains, and enables paid real-world actions like email and phone calls. This is not confirmed malware, but it carries elevated execution-trust and autonomy risk.

Confidence: 84%Severity: 73%
Audit Metadata
Analyzed At
Mar 13, 2026, 05:08 PM
Package URL
pkg:socket/skills-sh/merit-systems%2Fagentcash-skills%2Fagentcash%2F@bb0930cb58e49a6721d25badc1967e819dd523ab