nano-sign-message

Warn

Audited by Socket on May 3, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core purpose is coherent, but the skill couples sensitive signing operations with dynamic execution of an unpinned npm package whose official provenance was not verified in the provided evidence. The MCP tool path appears proportionate; the CLI --key path is the main risk because it hands raw private keys to remotely resolved code.

Confidence: 83%Severity: 82%
Audit Metadata
Analyzed At
May 3, 2026, 05:26 AM
Package URL
pkg:socket/skills-sh/CasualSecurityInc%2Fxno-skills%2Fnano-sign-message%2F@00c641d84ab0a88b1bcf812b2f060314660c5407