moneydevkit
Fail
Audited by Socket on Feb 28, 2026
1 alert found:
Obfuscated FileObfuscated FileSKILL.md
HIGHObfuscated FileHIGH
SKILL.md
No explicit malware or hardcoded secrets found in this document fragment. The main supply-chain/security issues are operational: unpinned npx usage (download-and-execute), broad declared capabilities (filesystem read + outbound network), and the sensitive nature of automated wallet agents managing mnemonics. Treat this as a medium security risk: audit and pin CLI packages, validate CLI source code before executing in sensitive environments, and apply strict key-custody and runtime isolation practices before deployment.
Confidence: 98%
Audit Metadata