alchemy-api
Fail
Audited by Socket on Mar 7, 2026
1 alert found:
Obfuscated FileObfuscated FileSKILL.md
HIGHObfuscated FileHIGH
SKILL.md
Overall, the skill presents a benign, purpose-aligned integration guide for Alchemy APIs. The most notable risk is the repeated use of API keys in URL paths within examples, which can lead to credential leakage if logs or intermediaries capture these URLs. As long as best practices (using headers, not logging keys, and securing environment variables) are followed, the footprint is proportionate to the described purpose. The guidance does not imply autonomous real-world actions, credential harvesting, or supply-chain risks beyond standard API usage. Recommend caution around logging and ensure credentials are never exposed in insecure channels or logs.
Confidence: 98%
Audit Metadata