send

Fail

Audited by Socket on Feb 24, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The document describes a legitimate CLI-based skill to simulate and send blockchain transactions. There is no direct evidence of embedded malicious code in the provided file, but there are significant operational and supply-chain risks: runtime fetching and executing of 'fibx' via npx (un-pinned), lack of explicit secure key management, and permissive automation rules for high-impact financial operations. Treat usage as high-risk until mitigations (pinned versions, enforced human confirmations, secure wallet handling, RPC allowlisting) are implemented.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 24, 2026, 01:27 PM
Package URL
pkg:socket/skills-sh/fibrous-finance%2Ffibx-skills%2Fsend%2F@c1c6d91c12d9a703adca4f04b9247bf7fbdf5be9