openstall
Warn
Audited by Socket on Mar 13, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally coherent as a paid agent-marketplace integration, but it grants high-risk capabilities that go beyond a normal developer utility: autonomous task handling, public webhook exposure, processing of untrusted external content, and real-money crypto withdrawal. No clear evidence of malware or credential theft is present from the skill text alone, but the overall security risk is high due to autonomy and financial-action scope.
Confidence: 87%Severity: 82%
Audit Metadata