portfolio

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill’s stated purpose and capabilities are broadly aligned: a read-only wallet portfolio command for Starknet. The main risk is install/execution trust from invoking an unpinned third-party CLI via `npx @latest`, plus opaque handling of authenticated session data. No clear evidence of malicious intent or disproportionate permissions is present, but the runtime dependency model makes this better classified as suspicious than fully benign.

Confidence: 80%Severity: 58%
Audit Metadata
Analyzed At
Mar 15, 2026, 04:43 PM
Package URL
pkg:socket/skills-sh/ahmetenesdur%2Fstarkfi%2Fportfolio%2F@b252ca7510855d5c7b36225d5ce2e4c4c8d127ec