pp-coingecko
Warn
Audited by Socket on May 8, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core purpose is coherent for read-only CoinGecko access, but the skill relies on external CLIs, unpinned installs, optional arbitrary webhook delivery, and MCP registration. These behaviors are not clearly malicious, yet they broaden trust and data-flow scope beyond a simple API query skill.
Confidence: 79%Severity: 56%
Audit Metadata