nansen-search

Fail

Audited by Socket on Mar 9, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill content is coherent with its stated purpose: it provides a command-line utility to search Nansen for tokens, wallets, or entities using an API key. The workflow involves standard dependency installation from npm and authenticated API calls. The primary security considerations are proper protection of the NANSEN_API_KEY (environment isolation, avoiding logs/history leakage) and ensuring the npm package is from a trusted source. No evidence of credential harvesting, unverified binary execution, or data exfiltration beyond the expected API data flow.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 9, 2026, 04:18 PM
Package URL
pkg:socket/skills-sh/nansen-ai%2Fnansen-cli%2Fnansen-search%2F@1f2d1a836ef3456f8712a6c1e5ad252a724d8dd4