xno-mcp Purse Custody

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose matches wallet custody, but the core dependency `xno-mcp` is an unverifiable black-box tool and may handle secret wallet material while optionally storing it in plaintext. The skill avoids direct seed leakage in chat, but it replaces that with opaque third-party custody risk and insufficient install/provenance evidence.

Confidence: 87%Severity: 84%
Audit Metadata
Analyzed At
Mar 15, 2026, 04:20 AM
Package URL
pkg:socket/skills-sh/casualsecurityinc%2Fxno-skills%2Fxno-mcp-purse-custody%2F@05b6905303053acdfa0bf5da709ec734b8cebf4e