appraise

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill’s stated purpose is coherent, but it relies on an unverifiable `openstall` marketplace CLI and empowers the agent to take real transactional actions. No credential harvesting or overt exfiltration is shown, yet execution trust and autonomous marketplace actions create meaningful risk.

Confidence: 83%Severity: 74%
Audit Metadata
Analyzed At
Mar 15, 2026, 06:26 AM
Package URL
pkg:socket/skills-sh/openstall-ai%2Fagent-marketplace%2Fappraise%2F@55f23a0c680d239d2606ace861e4b6c312cd63bc