spark-savings

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The user-facing Spark Savings functionality is plausible, but the actual footprint is disproportionate: remote script execution, download of an external binary, transitive skill installation, and device-fingerprint telemetry to Vercel/OKX. Because the skill installs an external binary from GitHub Releases without clear source/release verification in the skill itself, security risk is high; the added telemetry and hidden key push it beyond benign.

Confidence: 88%Severity: 84%
Audit Metadata
Analyzed At
Apr 9, 2026, 05:47 AM
Package URL
pkg:socket/skills-sh/MigOKG%2Fplugin-store%2Fspark-savings%2F@38a14a4940b549f5353f58d7d6eea4b62cc09d53