portfolio

Warn

Audited by Socket on Apr 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill's purpose and read-only wallet-portfolio behavior are broadly aligned, but it delegates core functionality to an unpinned third-party npm CLI (`npx fibx@latest`) with undocumented provenance and auth/session handling. That makes it suspicious from a supply-chain and session-forwarding perspective, though not overtly malicious based on the provided content.

Confidence: 76%Severity: 56%
Audit Metadata
Analyzed At
Apr 16, 2026, 08:58 AM
Package URL
pkg:socket/skills-sh/ahmetenesdur%2Ffibx-agentic-wallet-skills%2Fportfolio%2F@235559977a7956459632035a99928c5906644779