0xwork

Warn

Audited by Socket on Mar 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally coherent for a crypto task marketplace, uses a plausible official npm distribution path, and documents prompt-injection defenses. However, it grants an AI agent real wallet authority and autonomous financial/public marketplace actions, processes untrusted user content, and may route signing through a third-party service (Bankr), making the overall security risk high even without clear evidence of malware.

Confidence: 87%Severity: 78%
Audit Metadata
Analyzed At
Mar 27, 2026, 01:05 AM
Package URL
pkg:socket/skills-sh/BankrBot%2Fskills%2F0xwork%2F@b74b86daf1da15097be848c13be19e261f8025fa