across-protocol-ai-agent-skill

Warn

Audited by Socket on Feb 27, 2026

1 alert found:

Anomaly
AnomalyLOW
swap-api.md

The document is API integration documentation (not executable code) and contains no direct obfuscated or malicious code. However, it describes a flow where a remote service returns executable calldata (approvals and swap transactions) that clients are expected to submit. That pattern carries a meaningful supply-chain risk: if the API or an integrator is malicious or compromised, it can craft calldata to set allowances or transfer tokens to attacker-controlled addresses and cause fund loss. Therefore the content is not itself malware, but integrating clients must treat the API responses as untrusted: inspect calldata, minimize approvals, whitelist destination targets for embedded actions, and require explicit user consent before sending transactions.

Confidence: 90%Severity: 60%
Audit Metadata
Analyzed At
Feb 27, 2026, 11:21 AM
Package URL
pkg:socket/skills-sh/across-protocol%2Fskills%2Facross-protocol-ai-agent-skill%2F@4e5c2b4d42c99d5af4e5244d61697656e3e52cdd