taskmarket

Warn

Audited by Socket on Mar 5, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The fragment presents a plausible workflow for an on-chain task marketplace CLI but relies on a download-and-run bootstrap pattern that is a clear supply-chain risk vector. The risk is elevated due to wallet handling and in-memory signing without demonstrated integrity controls (code signing, pinned hashes, or version pinning). To improve security, replace the dynamic fetch/install pattern with verified, pinned versions, integrate code-signing or hash verification for skill.md and the CLI, and enforce sandboxed wallet handling with explicit user approvals for signing actions. Overall, risk remains elevated and warrants formal secure-by-design revisions before broader use.

Confidence: 65%Severity: 65%
Audit Metadata
Analyzed At
Mar 5, 2026, 06:41 AM
Package URL
pkg:socket/skills-sh/daydreamsai%2Fskills-market%2Ftaskmarket%2F@6bb4981e1262d1d0bf81f7e9b35d4cb75c02032e