send-token

Warn

Audited by Socket on Mar 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s capabilities align with its stated purpose, but it authorizes high-impact financial actions and relies on an unpinned external CLI fetched via `npx @latest`. This is not confirmed malware, but it carries elevated security risk from mutable supply chain trust and irreversible fund transfers.

Confidence: 86%Severity: 74%
Audit Metadata
Analyzed At
Mar 14, 2026, 02:18 AM
Package URL
pkg:socket/skills-sh/openant-ai%2Fopenant-skills%2Fsend-token%2F@3583e4fdc604e63c6c73ecab34e026eef043ee1b