blockchain-auditor

Fail

Audited by Socket on Mar 8, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill aligns with its stated purpose of blockchain security auditing and PoC exploration in forks, but it introduces notable security considerations. It relies on downloading external tooling, uses environment credentials, and describes exploit-generation workflows that could be misused if not properly authorized and sandboxed. The data flows primarily involve legitimate data sources (Etherscan, 4byte, RPCs) and controlled fork testing; however, the combination of potentially exploitative actions and external tooling introduces supply-chain and credential-exposure risks. Overall, the footprint is suspiciously high for a purely auditing tool but not clearly malicious; treat as SUSPICIOUS with emphasis on implementing strict access controls, credential protection, and explicit authorization boundaries before deploying in any real environment.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 8, 2026, 12:12 AM
Package URL
pkg:socket/skills-sh/ckorhonen%2Fclaude-skills%2Fblockchain-auditor%2F@94e8920fc2de89daffe3530aa6f7f6c4621b4c74