batch

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s capabilities match its DeFi batching purpose, but it enables high-impact autonomous financial actions and relies on an unpinned external CLI (`npx starkfi@latest`). No explicit credential theft or exfiltration is shown, so this is not confirmed malware, but it is a high-risk skill due to real-world transaction authority and mutable supply-chain trust.

Confidence: 80%Severity: 79%
Audit Metadata
Analyzed At
Mar 15, 2026, 04:43 PM
Package URL
pkg:socket/skills-sh/ahmetenesdur%2Fstarkfi%2Fbatch%2F@e9fec29a5d7ed1e229fcfe01c2c42492a274bf3c