paystack-verification
Audited by Socket on Mar 8, 2026
1 alert found:
Obfuscated FileThe skill's described capabilities (account resolution, validation, BIN lookup) are coherent with its stated purpose and involve data flows typical of a payment-provider KYC workflow. There is no evident misuse of credentials, no unsolicited data exfiltration, and no aggressive download/install behavior within the provided snippet. The primary risk hinges on how credentials are sourced and managed by the paystackRequest helper; if API keys are fetched from insecure locations, the risk increases. Overall, the footprint is Benign with minor risk due to dependency management unknowns. Treat as Suspicious if dependencies are retrieved from unverifiable sources or if keys are exposed in logs or through insecure storage; otherwise, consider it Benign.