four-meme-ai

Warn

Audited by Socket on Mar 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally consistent with its stated purpose, but that purpose is inherently high risk: it gives an AI agent broad cryptocurrency trading and transfer powers using a raw private key. Install provenance looks plausible via npm and a public repo, and no clear exfiltration endpoint is shown, so this is not confirmed malware; however, the combination of private-key handling and autonomous on-chain actions makes the overall security risk high.

Confidence: 89%Severity: 78%
Audit Metadata
Analyzed At
Mar 31, 2026, 10:07 AM
Package URL
pkg:socket/skills-sh/four-meme-community%2Ffour-meme-ai%2Ffour-meme-ai%2F@bf825471f5031c2505580cf98af44a3498fb91bf