secondme
Warn
Audited by Socket on Apr 3, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: Most capabilities align with a SecondMe user workflow and the API endpoint appears first-party, so this is not clearly malicious. The main risks are the silent auto-update behavior, raw credential-file handling, and especially the built-in ability to install additional third-party skills, which expands trust beyond the stated core workflow.
Confidence: 84%Severity: 72%
Audit Metadata