secondme

Warn

Audited by Socket on Apr 3, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: Most capabilities align with a SecondMe user workflow and the API endpoint appears first-party, so this is not clearly malicious. The main risks are the silent auto-update behavior, raw credential-file handling, and especially the built-in ability to install additional third-party skills, which expands trust beyond the stated core workflow.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Apr 3, 2026, 06:47 AM
Package URL
pkg:socket/skills-sh/mindverse%2Fsecond-me-skills%2Fsecondme%2F@fd317a70b1df6a41d8cdd9d0956f3fe25d055031