nano-sign-message
Warn
Audited by Socket on May 3, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the core purpose is coherent, but the skill couples sensitive signing operations with dynamic execution of an unpinned npm package whose official provenance was not verified in the provided evidence. The MCP tool path appears proportionate; the CLI --key path is the main risk because it hands raw private keys to remotely resolved code.
Confidence: 83%Severity: 82%
Audit Metadata