solidity-code-verification

Warn

Audited by Socket on Apr 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose—remote Solidity security analysis—is plausible, and sending contract code to an analyzer is proportionate. But the skill's actual footprint is mainly to install and rely on a separate third-party ACP skill/CLI from another GitHub org, with opaque service routing and a transitive trust chain. Main risk is supply-chain and indirect data flow, not confirmed malware.

Confidence: 86%Severity: 78%
Audit Metadata
Analyzed At
Apr 7, 2026, 04:39 PM
Package URL
pkg:socket/skills-sh/cybercentry%2Fcybercentry-agent-skills%2Fsolidity-code-verification%2F@278018c9a457a339f6ed9cc9749c872f04d9e851