nano-mcp-wallet

Warn

Audited by Socket on May 3, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is purpose-aligned for Nano wallet custody, but it carries high operational risk because it empowers an AI agent to perform real blockchain transactions and encourages remote execution of an unpinned package (`xno-skills@latest`) whose provenance is not clearly established in the provided evidence. I do not see strong evidence of credential theft or overt malware, but the combination of financial autonomy and mutable supply-chain execution makes this a high-risk skill.

Confidence: 84%Severity: 81%
Audit Metadata
Analyzed At
May 3, 2026, 05:26 AM
Package URL
pkg:socket/skills-sh/CasualSecurityInc%2Fxno-skills%2Fnano-mcp-wallet%2F@563b62e0d23e3860fe49f75d8ce0a24f7ac3e0d6