blockrun
Fail
Audited by Socket on Mar 10, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
Overall, the BlockRun skill appears to be a benign, purpose-aligned extension enabling image generation, real-time data, and second opinions through paid external services via a wallet. The install source is trustworthy (PyPI), and data flows align with the stated capabilities. While there are autonomous decision patterns and wallet-driven cost controls, these are within the intended scope of the feature. No clear credential harvesting, hidden exfiltration, or rogue supply-chain behavior is evident from the provided material. Monitor per-call costs and ensure explicit user confirmation or budgeting UI is presented to avoid surprise charges.
Confidence: 98%Severity: 25%
Audit Metadata