sorin-skill

Warn

Audited by Socket on Mar 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s stated crypto-analysis purpose is plausible, but its actual data flow depends on an undocumented proxy domain that receives the user’s bearer token. With no verified link between the proxy and the official Sorin/Sahara publisher, the main risk is credential interception and opaque man-in-the-middle API routing rather than overt malware.

Confidence: 91%Severity: 81%
Audit Metadata
Analyzed At
Mar 31, 2026, 07:58 AM
Package URL
pkg:socket/skills-sh/SaharaLabsAI%2Fskills%2Fsorin-skill%2F@220d541cd76c7f3d96c1064a1d4ccacd396417b4