send
Fail
Audited by Socket on Feb 24, 2026
1 alert found:
Obfuscated FileObfuscated FileSKILL.md
HIGHObfuscated FileHIGH
SKILL.md
The document describes a legitimate CLI-based skill to simulate and send blockchain transactions. There is no direct evidence of embedded malicious code in the provided file, but there are significant operational and supply-chain risks: runtime fetching and executing of 'fibx' via npx (un-pinned), lack of explicit secure key management, and permissive automation rules for high-impact financial operations. Treat usage as high-risk until mitigations (pinned versions, enforced human confirmations, secure wallet handling, RPC allowlisting) are implemented.
Confidence: 98%
Audit Metadata