erwa-api
Warn
Audited by Socket on Apr 17, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated purpose is coherent for a Web3 data API, but the trust and data-flow model are not proportionate: installation comes from an unverified third-party skill repo, tokens are obtained manually via WeChat, and all authenticated traffic uses insecure HTTP/WS to a bare IP. The biggest risk is credential exposure and interception, not confirmed malware.
Confidence: 90%Severity: 86%
Audit Metadata