ethskills

Warn

Audited by Socket on Mar 26, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
orchestration/SKILL.md

BENIGN for stated purpose as a framework/orchestration guide, but HIGH operational risk if granted to an autonomous agent because it enables wallet-backed blockchain transactions, payments, and public deployment. No clear credential exfiltration or deceptive routing is shown; the main concern is real-world financial action and untrusted endpoint interaction.

Confidence: 86%Severity: 74%
SecurityMEDIUM
audit/SKILL.md

SUSPICIOUS: the skill’s purpose matches its capabilities, but it materially increases agent risk by enabling security-audit tradecraft, fetching transitive remote skill content, processing untrusted repository text, and taking external actions via GitHub issue filing. No direct credential harvesting or clear exfiltration is shown, so this is high-risk vulnerable behavior rather than confirmed malware.

Confidence: 86%Severity: 74%
Audit Metadata
Analyzed At
Mar 26, 2026, 04:48 PM
Package URL
pkg:socket/skills-sh/involvex%2Faetheris%2Fethskills%2F@4cb0ed11167bb4f83122d488eda5bf388f1db748