renzo

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core Renzo functionality is plausible, but the actual footprint is broader than necessary: auto-install of third-party CLIs/skills, download of an unverifiable renzo binary, and install-time device fingerprint reporting to Vercel and OKX. The financial-transaction purpose partly explains wallet tooling, but the telemetry and transitive installs are disproportionate and weaken trust.

Confidence: 90%Severity: 85%
Audit Metadata
Analyzed At
Apr 9, 2026, 05:46 AM
Package URL
pkg:socket/skills-sh/MigOKG%2Fplugin-store%2Frenzo%2F@5e33dd6da422d34c8b5ea726a48916afc7d860ec