agent-vegas

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally coherent as an Agent Vegas integration, but it grants an AI agent autonomous third-party account creation, betting, and paid actions, while proactively exposing an observation link and persisting credentials for a weakly verifiable service. No malware or installer behavior is shown, but the autonomy and trust model make it high risk.

Confidence: 84%Severity: 78%
Audit Metadata
Analyzed At
Mar 18, 2026, 06:54 PM
Package URL
pkg:socket/skills-sh/romejiang%2Fagentvegas%2Fagent-vegas%2F@6b98522dba1688611d81da11d9dc2ce32fb248e4