client-dev

Fail

Audited by Socket on Mar 11, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's footprint is coherent with its stated purpose of building MCP clients that connect to ContextVM servers over the Nostr network. It uses standard, verifiable dependencies from official registries and relies on environment-provided credentials in a controlled manner. Data flows involve legitimate network communication to Nost relays and server endpoints, which is aligned with the intended functionality. While there is normal network data movement and credential usage (private key from environment), there are no suspicious or unverifiable binaries, no hidden data exfiltration paths, and no autonomous actions beyond explicit user calls. Overall, the skill is BENIGN with moderate operational risk due to credential handling and network exposure.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 11, 2026, 02:11 AM
Package URL
pkg:socket/skills-sh/contextvm%2Fcvmi%2Fclient-dev%2F@034209d2d93bcb37f0ea9ee9efae723771d10906