portfolio
Warn
Audited by Socket on Apr 28, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is coherent with its stated crypto portfolio purpose, but it carries substantial security risk because it executes a third-party CLI from a mutable npm tag and can perform autonomous financial transactions after authentication. This looks more like a high-risk wallet/trading integration than malware, but it should only be used with explicit per-action approval and strong trust in the StarkFi service stack.
Confidence: 84%Severity: 78%
Audit Metadata