config

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s stated purpose matches its capabilities, but it relies entirely on an unpinned external npm CLI (`npx starkfi@latest`). That creates meaningful supply-chain risk, and RPC URLs with embedded provider keys may be exposed to the CLI. No clear malicious or exfiltration behavior is shown in the skill text itself.

Confidence: 81%Severity: 57%
Audit Metadata
Analyzed At
Mar 15, 2026, 04:45 PM
Package URL
pkg:socket/skills-sh/ahmetenesdur%2Fstarkfi%2Fconfig%2F@43897923ab7b12ce3f57586050c67247723a44fd