canister-security

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The Canister Security skill is largely benign and coherent with its stated purpose: it provides IC canister security patterns (access control, reentrancy guards, async safety, upgrade cautions) for Motoko and Rust. Its footprint—no unverified binaries, no credential harvesting, and no external exfiltration—and its focus on defensive coding patterns are proportionate to the described goal. Some sections require careful implementation by developers to avoid TOCTOU and trap-related pitfalls, but the content remains guidance-focused rather than actionable exploits. Overall, classify as BENIGN with caution about proper implementation in real systems.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 02:24 AM
Package URL
pkg:socket/skills-sh/dfinity%2Ficskills%2Fcanister-security%2F@f2a20d7cb72ae2c61d9cd9259ec2d09fc4a100cb