agent-tool

Warn

Audited by Socket on Feb 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The provided code segment outlines a coherent refund-and-access-revocation tool but contains concrete runtime risks (undefined variables, ambiguous approval semantics, and missing validation). Fixing the undefined purchase reference, clarifying auto-approval behavior, and adding input validation, idempotency, and secure handling of credentials are essential before deployment. Overall, the security risk is moderate with concrete execution-time risks; treat as requiring remediation before production use.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 28, 2026, 10:35 PM
Package URL
pkg:socket/skills-sh/skillrecordings%2Fsupport%2Fagent-tool%2F@711af069133357e433c4c123a75252b06c6c47de