blockrun

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

Overall, the BlockRun skill appears to be a benign, purpose-aligned extension enabling image generation, real-time data, and second opinions through paid external services via a wallet. The install source is trustworthy (PyPI), and data flows align with the stated capabilities. While there are autonomous decision patterns and wallet-driven cost controls, these are within the intended scope of the feature. No clear credential harvesting, hidden exfiltration, or rogue supply-chain behavior is evident from the provided material. Monitor per-call costs and ensure explicit user confirmation or budgeting UI is presented to avoid surprise charges.

Confidence: 98%Severity: 25%
Audit Metadata
Analyzed At
Mar 10, 2026, 01:14 AM
Package URL
pkg:socket/skills-sh/claudiodearaujo%2Fizacenter%2Fblockrun%2F@169cb5ea4c4c7dbd28eefc212842fca339ea769e