extension-payment

Warn

Audited by Socket on Mar 27, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The stated purpose is legitimate and mostly aligned with payment integration, but the skill expands trust by requiring a transitive docs-seeker skill and likely routing doc retrieval through Context7. Its credential request is somewhat broader than necessary, and external-doc ingestion plus implementation guidance raises prompt-injection and third-party data-flow risk. No direct malware indicators or overt exfiltration are present.

Confidence: 85%Severity: 58%
Audit Metadata
Analyzed At
Mar 27, 2026, 01:46 PM
Package URL
pkg:socket/skills-sh/quangpl%2Fbrowser-extension-skills%2Fextension-payment%2F@fb75b3a58adc26a36f26ccdc4924496c12c9167a