cardano-identity

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's stated purpose (resolve and list ADAHandles for the connected Cardano wallet) is coherent with its capabilities and dependencies. The main security considerations center on handling the wallet seed phrase securely and ensuring the MCP tool is trusted and properly sandboxed. While largely proportionate, the documented reliance on SEED_PHRASE and an external npm package warrants careful secret management and verification of the MCP server and package integrity. Overall, the skill is BENIGN with elevated risk due to credential handling; treat as SUSPICIOUS if logs or external transmissions of seed phrases are implied or if the MCP server is not trusted.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 11:31 AM
Package URL
pkg:socket/skills-sh/IndigoProtocol%2Fcardano-ai%2Fcardano-identity%2F@5d06594a67453e1fcebaac739e8fc1f56b8f79d0