portfolio

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is coherent with its stated crypto portfolio purpose, but it carries substantial security risk because it executes a third-party CLI from a mutable npm tag and can perform autonomous financial transactions after authentication. This looks more like a high-risk wallet/trading integration than malware, but it should only be used with explicit per-action approval and strong trust in the StarkFi service stack.

Confidence: 84%Severity: 78%
Audit Metadata
Analyzed At
Apr 28, 2026, 11:54 AM
Package URL
pkg:socket/skills-sh/ahmetenesdur%2Fstarkfi%2Fportfolio%2F@6ba2a166a8b9e702be19aa71e8a4af1c7b9af2db