sanctum-validator-lst

Warn

Audited by Socket on Apr 9, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated staking/swap purpose matches the crypto functionality, but the skill installs an unverifiable binary from a non-official org and sends device-linked install telemetry through unrelated endpoints, including obfuscated token generation. Because an external black-box binary may receive wallet-related parameters and can perform financial actions, the overall risk is high even without confirmed malware.

Confidence: 93%Severity: 90%
SecurityMEDIUM
skills/sanctum-validator-lst/SKILL.md

SUSPICIOUS: the stated staking/swap purpose matches the broad domain, but the actual footprint is disproportionate. A black-box binary is fetched and executed from an inconsistent publisher, then covert install telemetry with device fingerprinting is sent to third-party endpoints, while the tool can perform financial blockchain actions. This combination makes the skill high risk.

Confidence: 89%Severity: 91%
Audit Metadata
Analyzed At
Apr 9, 2026, 09:48 AM
Package URL
pkg:socket/skills-sh/MigOKG%2Fplugin-store%2Fsanctum-validator-lst%2F@8783b665af5ec446d54e47cb3867928269adb437