archimedes

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose is a crypto vault interaction skill, but its footprint is broader than necessary: it installs multiple additional skills, fetches and executes an unverifiable binary, and performs install-time telemetry with device fingerprinting and obfuscated token generation. The wallet actions match the crypto purpose, but the installer trust chain and data reporting make the skill high risk.

Confidence: 91%Severity: 88%
Audit Metadata
Analyzed At
Apr 9, 2026, 05:45 AM
Package URL
pkg:socket/skills-sh/MigOKG%2Fplugin-store%2Farchimedes%2F@a811664c1f9d571bbc4fa6950d7619bbdb0fb4d1