nipper

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill. Its stated marketplace purpose is plausible, but the footprint is broader than simple API documentation: it installs a transitive skill, pulls an unverified remote SDK tarball, and enables autonomous financial actions with wallet keys and payment signatures. The main concern is supply-chain and financial-action risk rather than confirmed malware.

Confidence: 84%Severity: 83%
Audit Metadata
Analyzed At
Mar 15, 2026, 12:53 PM
Package URL
pkg:socket/skills-sh/nipper-ai%2Fclaude-plugin%2Fnipper%2F@7cdf7fb330fe8c65905a27dfad70ae2066971191