xapi

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s stated purpose matches its capabilities, and the npm install path looks plausible, but its actual footprint is high-risk because it centralizes many external services behind xapi.to, forwards credentials through that intermediary, supports autonomous public posting, and includes a payment flow that can reveal the API key in a URL. This is better classified as a risky proxy/integration skill than malware.

Confidence: 84%Severity: 78%
Audit Metadata
Analyzed At
Mar 13, 2026, 02:34 PM
Package URL
pkg:socket/skills-sh/xapi-labs%2Fskills%2Fxapi%2F@908d20ce6553acb367d47db39a70e233b3598ff4