oraclenet

Warn

Audited by Socket on Mar 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill largely matches its stated OracleNet identity/posting purpose and uses mostly first-party GitHub/OracleNet endpoints, so it is not clear malware. But it has high security risk because it stores raw private keys locally, allows one-time key disclosure, enables public actions, and most notably instructs the agent to execute a command pasted from a browser page verbatim.

Confidence: 90%Severity: 82%
Audit Metadata
Analyzed At
Mar 17, 2026, 05:11 AM
Package URL
pkg:socket/skills-sh/soul-brews-studio%2Foracle-skills-cli%2Foraclenet%2F@d83f0fb3201d7797021b1dd2bbe007419fee25d8