blockrun

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS — The skill's described functionality (auto-creating/using a wallet to route paid calls to external LLM/image/realtime search providers) is coherent with its stated purpose, but the documentation lacks key security details: it does not name endpoints or gateway operators, does not describe how wallet private keys are protected, and implies prompts/requests are routed through a payment-mediation layer rather than direct provider APIs. Those omissions create notable risks: potential data exposure of user prompts, theft of wallet funds if keys or gateway are malicious/compromised, and lack of verifiability of where data and payments go. There is no direct evidence of malware in the text, but the opaque payment/proxy model and the storing of sensitive session data locally justify treating this skill as suspicious until more implementation detail and provenance (publisher identity, audited endpoints, client-side key handling/encryption) are provided.

Confidence: 65%Severity: 60%
Audit Metadata
Analyzed At
Feb 15, 2026, 08:12 PM
Package URL
pkg:socket/skills-sh/davila7%2Fclaude-code-templates%2Fblockrun%2F@169cb5ea4c4c7dbd28eefc212842fca339ea769e