cardano-staking

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill aligns with its stated purpose of checking Cardano stake delegation and rewards, but it introduces a notable credential exposure risk by requiring SEED_PHRASE in the environment. The overall threat posture is MEDIUM with a leaning toward SUSPICIOUS due to potential credential leakage and ambiguous supply-chain assurances. If implemented, ensure secret handling is strictly confined, secrets are never logged, and the MCP client is from a verified source with verifiable integrity (signatures, pinned version, or a vetted internal registry).

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 11:31 AM
Package URL
pkg:socket/skills-sh/IndigoProtocol%2Fcardano-ai%2Fcardano-staking%2F@bf0c49483884a9f5734fff55002d6eacbbfb2e78