clankerkit

Warn

Audited by Socket on Feb 26, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
skill.json

This JSON manifest itself contains no executable or obfuscated malicious code, but documents powerful wallet operations that require a private key and allow arbitrary on-chain transactions and payments. The highest practical risk is misuse or theft of AGENT_PRIVATE_KEY and invocation of the 'execute_transaction' or transfer tools to drain funds or pay attacker-controlled endpoints. Treat this package as high-privilege: require secure secret handling, strict owner approvals, input validation and audits before deployment.

Confidence: 90%Severity: 60%
SecurityMEDIUM
SKILL.md

The clankerkit manifest presents a legitimate autonomous wallet automation objective but introduces substantial risk due to broad privileged capabilities, secret handling, and multiple external dependencies. Strong governance, least-privilege isolation, per-action consent, strict secret management, and auditability are essential before any production use. Treat as HIGH-RISK with recommended mitigations: remove or minimize private-key exposure, implement per-action approvals, harden policy checks, isolate external API calls, and enable comprehensive monitoring.

Confidence: 65%Severity: 78%
Audit Metadata
Analyzed At
Feb 26, 2026, 04:20 PM
Package URL
pkg:socket/skills-sh/openclaw%2Fskills%2Fclankerkit%2F@18fc7ad8a9e9827337fe929896288ca04c5358b2