openfin-onchain

Warn

Audited by Socket on May 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is broadly aligned with its stated crypto purpose, but it grants an AI agent the ability to trigger irreversible token transfers from an embedded wallet. The main risks are autonomous financial action, unclear publisher/install provenance for the prerequisite setup, and transitive trust in other OpenFin skills/services rather than obvious credential theft or covert exfiltration.

Confidence: 81%Severity: 67%
Audit Metadata
Analyzed At
May 12, 2026, 08:02 PM
Package URL
pkg:socket/skills-sh/openfinance-tech%2Fskills%2Fopenfin-onchain%2F@fa316b19f7fcdf936ccea9ff3f0877e345d11385