walletconnect-agent

Warn

Audited by Socket on Apr 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s stated purpose matches its capabilities, but that purpose is itself high risk: it gives an AI agent autonomous control over a cryptocurrency wallet for irreversible blockchain actions. Install sources are mostly legitimate npm packages, yet the skill depends on a deprecated WalletConnect package and requires a raw private key for an unseen local script, creating substantial credential and financial risk even without clear evidence of malware or exfiltration.

Confidence: 90%Severity: 91%
Audit Metadata
Analyzed At
Apr 27, 2026, 11:04 PM
Package URL
pkg:socket/skills-sh/dAAAb%2Fagent-skills%2Fwalletconnect-agent%2F@a6d1067b3ba9d9e313aec0a7fddec92c78ba0b24