fuel

Fail

Audited by Socket on Feb 28, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The fragment presents a coherent, legitimate workflow for provisioning and configuring a cost-optimized multi-provider inference setup (Fuel) with Stripe-based payments, VK provisioning, and local config updates. No hardcoded secrets are present; placeholders indicate user-supplied credentials. The main risk stems from external network interactions and credential handling, which require robust secret management, logging controls, and secure storage. Overall, the risk is moderate: monitor for credential leakage and ensure secure handling of VKs and payment data rather than labeling as malware; treat as SUSPICIOUS-to-MONITORING until secret-management controls are verified.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 28, 2026, 04:35 PM
Package URL
pkg:socket/skills-sh/openclaw-rocks%2Fskills%2Ffuel%2F@00fb9ecde9aa1c092e5b2e09e38f2bb48ce85e26