dune-to-allium

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose and requested credentials broadly match SQL conversion and API-backed result comparison, and the documented endpoints are official Dune/Allium destinations. However, it instructs the agent to read raw credential files and execute unreviewed local helper scripts, so the real data handling cannot be fully verified from the skill text alone. Risk is moderate rather than clearly malicious.

Confidence: 79%Severity: 56%
Audit Metadata
Analyzed At
Mar 13, 2026, 08:42 AM
Package URL
pkg:socket/skills-sh/allium-labs%2Fskills%2Fdune-to-allium%2F@145ea3ccc7b27257367369f38a35f3ba5b3d46c1