symbiosis

Warn

Audited by Socket on Mar 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is largely coherent with its stated purpose: a crypto bridge/swap skill should contact Symbiosis and submit transactions through Bankr, and the documented data flows mostly match official services. However, it enables autonomous real-world financial actions and reads a local Bankr credential to authorize wallet-affecting API calls, which makes the security impact high even without evidence of malware or exfiltration.

Confidence: 88%Severity: 74%
Audit Metadata
Analyzed At
Mar 31, 2026, 06:22 AM
Package URL
pkg:socket/skills-sh/BankrBot%2Fskills%2Fsymbiosis%2F@ea34d5c4462d501660d9f059f286c234e96c8b28