multi-canister

Warn

Audited by Socket on Mar 11, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Overall, the skill is Benign-to-Suspicious in intent: it presents a coherent blueprint for multi-canister IC architectures but includes a highly sensitive and under-specified capability—the ability for callers to supply and install arbitrary WASM via a canister factory. This capability is a severe supply-chain and remote-execution risk if not tightly controlled. The rest of the architecture (inter-canister calls, upgrade readiness, and cross-canister data flows) is aligned with the stated purpose, but the dynamic code installation pattern elevates the risk profile to Suspicious, with a need for stringent access controls, module verification, and clear operational boundaries before considering it safe for production use.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 11, 2026, 07:17 AM
Package URL
pkg:socket/skills-sh/dfinity%2Ficskills%2Fmulti-canister%2F@99972d9a22fdf1c6cf96835562e0d5f174f1393e