splitwise-cli

Warn

Audited by Socket on Mar 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill mentions saving credentials to a config file and environment variables, which enables potential exfiltration if the agent copies or transmits these credentials without user consent or explicit per-call authorization.

Confidence: 80%Severity: 75%
Audit Metadata
Analyzed At
Mar 9, 2026, 02:02 AM
Package URL
pkg:socket/skills-sh/oristides%2Fsplitwisecli%2Fsplitwise-cli%2F@75ada2f7aa3b154373b56803e5307e71a4021ddf