finance-district
Warn
Audited by Socket on Apr 18, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is purpose-aligned and uses an official, verifiable same-brand CLI, so there is no strong evidence of malware or deceptive credential exfiltration. However, it grants an AI agent broad cryptocurrency and merchant-payment powers with real financial consequences, including wallet transfers, swaps, DeFi deposits, x402 payment signing, and API key management, making it high-impact even though the install path is legitimate.
Confidence: 89%Severity: 73%
Audit Metadata