blockrun

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: the skill’s purpose is coherent, but its footprint is high risk because it enables autonomous real-money spending, stores and uses a local wallet, and routes user data through a third-party gateway rather than direct official APIs. The PyPI install path is less concerning than the payment autonomy and intermediary data flow.

Confidence: 84%Severity: 81%
Audit Metadata
Analyzed At
Mar 18, 2026, 04:50 PM
Package URL
pkg:socket/skills-sh/davila7%2Fclaude-code-templates%2Fblockrun%2F@169cb5ea4c4c7dbd28eefc212842fca339ea769e