arkade

Warn

Audited by Socket on Feb 25, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill documentation and examples are coherent with their stated purpose and do not contain obvious malicious code or hidden exfiltration patterns. Primary risks are operational: handling of private keys (examples show in-code keys), trust in operator and Boltz endpoints, and the fact that SDK methods can perform real financial actions. Recommendations: never hardcode private keys, use secure key management, review and trust the operator and swap providers before using in production, and audit the actual npm packages' code and dependency chain before deployment.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 25, 2026, 05:46 PM
Package URL
pkg:socket/skills-sh/arkade-os%2Fskill%2Farkade%2F@a49dac3a6194f09993b5d38e17c22372765af1de