sorin-skill
Warn
Audited by Socket on Mar 31, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s stated crypto-analysis purpose is plausible, but its actual data flow depends on an undocumented proxy domain that receives the user’s bearer token. With no verified link between the proxy and the official Sorin/Sahara publisher, the main risk is credential interception and opaque man-in-the-middle API routing rather than overt malware.
Confidence: 91%Severity: 81%
Audit Metadata