tax

Fail

Audited by Socket on Mar 21, 2026

2 alerts found:

AnomalyObfuscated File
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's core purpose and requested capabilities are mostly aligned, but advanced features route sensitive tax data to a third-party hosted SerenDB service and forward Kraken credentials to local scripts whose code is not shown. There is no obvious malware pattern or overt exfiltration endpoint mismatch, but dependency provenance and actual credential/data handling are insufficiently verifiable, making this a medium-risk skill rather than clearly benign.

Confidence: 82%Severity: 58%
Obfuscated FileHIGH
scripts/serendb_store.py

This module appears to be a buggy / truncated client and DB helper library for Serendb rather than intentionally malicious code. I found no clear indicators of backdoors, remote shells, or covert exfiltration beyond legitimate API calls to api.serendb.com. The file contains multiple syntax and logic errors and undefined variables; it is not operational as provided. Security recommendations: do not run this code in production until fixed; avoid exposing exception messages containing secrets; prefer parameterized SQL for all identifiers where possible or strictly enforce immutable allowlists; and validate any fixes for injection or accidental credential leakage.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 21, 2026, 02:45 AM
Package URL
pkg:socket/skills-sh/serenorg%2Fseren-skills%2Ftax%2F@79df33c329fb97a9a010262791bf30b226e3a838