emblem-token-swap

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is purpose-aligned, but its purpose is inherently high-risk: it enables an AI agent to perform real cryptocurrency swaps and bridges through an installed external CLI and a third-party bridge provider. The npm install path appears relatively legitimate rather than overtly malicious, yet the combination of value-moving autonomy, external CLI trust, and intermediary routing makes the overall security risk high even without clear evidence of credential theft or malware.

Confidence: 83%Severity: 76%
Audit Metadata
Analyzed At
Apr 10, 2026, 08:13 AM
Package URL
pkg:socket/skills-sh/emblemcompany%2Fagent-skills%2Femblem-token-swap%2F@3ed048fd7723b1ac5530f78127b27fc2e24c5986