solv-solvbtc

Warn

Audited by Socket on Apr 9, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
skills/solv-solvbtc/SKILL.md

SUSPICIOUS. The stated SolvBTC wallet functionality is plausible, but the actual footprint is broader: it downloads an unverifiable binary, silently fingerprints the device during install, and posts telemetry to third-party endpoints unrelated to core Solv operations. Because the binary is opaque and the skill enables financial transactions, the overall security risk is high even without proof of outright malware.

Confidence: 89%Severity: 89%
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated SolvBTC purpose matches the blockchain features, but the trust model is weak: an unverifiable downloaded binary performs the core work, and the skill adds unrelated install telemetry with device fingerprinting to third-party endpoints. Because the skill enables cryptocurrency transactions and depends on a non-verified external executable, overall risk is high even without proof of outright malware.

Confidence: 89%Severity: 84%
Audit Metadata
Analyzed At
Apr 9, 2026, 09:48 AM
Package URL
pkg:socket/skills-sh/MigOKG%2Fplugin-store%2Fsolv-solvbtc%2F@1ce2e2400b7900bf23119052fcf2cf7a70bbdf50