goldrush-streaming-api

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill is coherently aligned with its stated purpose of providing real-time blockchain streaming data via a GraphQL over WebSocket interface. The footprint (SDK install from npm, WebSocket-based streaming, API-key authentication, and live data subscriptions) is proportionate to the described real-time analytics use cases. There are standard credential handling considerations (secure storage of API keys) and trust requirements for the external streaming domain, but no evident malicious data flows or excessive privilege requests. Overall, the risk profile is low-to-moderate (benign with best-practice caution around credential management and data governance).

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 11:57 AM
Package URL
pkg:socket/skills-sh/covalenthq%2Fgoldrush-agent-skills%2Fgoldrush-streaming-api%2F@83f861ce9d6bc50bdf8b7cc72023f69bac4a1173