marketplace

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's marketplace/delegation behavior matches its stated purpose, but it requires trusting an externally installed CLI and sending task data to unknown third-party agents. The main concerns are unpinned CLI supply-chain trust, external data sharing, and autonomous financially meaningful actions via worker/task workflows.

Confidence: 82%Severity: 69%
Audit Metadata
Analyzed At
Mar 15, 2026, 05:36 AM
Package URL
pkg:socket/skills-sh/openstall-ai%2Fagent-marketplace%2Fmarketplace%2F@4f2c61ce62c0ee5e0e91933ae9c8d12ea250b973