wallet-verification

Warn

Audited by Socket on Apr 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s purpose is plausible and the requested wallet input is proportionate, but its execution model is not tightly aligned with the publisher: Cybercentry instructs installation of a separate Virtual-Protocol ACP CLI that handles setup, token storage, provider discovery, and job submission. That mediated trust chain and credential handling create meaningful supply-chain and credential-forwarding risk, even without clear evidence of malware.

Confidence: 85%Severity: 80%
Audit Metadata
Analyzed At
Apr 7, 2026, 04:39 PM
Package URL
pkg:socket/skills-sh/cybercentry%2Fcybercentry-agent-skills%2Fwallet-verification%2F@8c838a4449e2c1e9b18d397b1469f3cdcce5b521