bsocial

Warn

Audited by Socket on Mar 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The capability matches the stated BSocial purpose, but the skill is high risk because it lets the agent take autonomous public blockchain actions and encourages handling a raw WIF on the command line. The third-party Railway API is purpose-consistent but weakens data-flow trust. This looks more like a hazardous blockchain/posting skill than malware.

Confidence: 86%Severity: 72%
Audit Metadata
Analyzed At
Mar 14, 2026, 04:00 PM
Package URL
pkg:socket/skills-sh/b-open-io%2Fbsv-skills%2Fbsocial%2F@db611ca964dad64564b223202d3d1c1c8e1ef3f3