revolut

Fail

Audited by Socket on Mar 1, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This appears to be a legitimate Revolut Business API CLI that requires high-value credentials (private RSA key and OAuth tokens) and can perform high-impact operations (payments, transfers). The primary security concerns are operational: protecting the private key and refresh tokens on disk, preventing automated misuse via the confirmation-bypass flag, and verifying that the implementation communicates only with official Revolut endpoints over TLS. There is no evidence in the provided fragment of malware, obfuscation, or data-exfiltration backdoors, but a full review of the implementation (network endpoints, HTTP client code, and third-party dependencies) is recommended before trusting the tool for automated or elevated use.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 1, 2026, 05:16 AM
Package URL
pkg:socket/skills-sh/ThinkfleetAI%2Fthinkfleet-engine%2Frevolut%2F@c06578dd4b3ebf7efdc81dcea19278fd54a997ea