openfort

Warn

Audited by Socket on Apr 12, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is mostly aligned with Openfort development and uses same-org official tooling, so it does not look malicious. However, it materially expands from documentation into authenticated wallet and transaction operations, giving an AI agent financial-action capability and access to sensitive wallet/API credentials; that makes the skill high-impact and risky even without evidence of exfiltration.

Confidence: 86%Severity: 74%
Audit Metadata
Analyzed At
Apr 12, 2026, 07:17 AM
Package URL
pkg:socket/skills-sh/openfort-xyz%2Fagent-skills%2Fopenfort%2F@a3a8b2cb458fb049875e812005bd5be625bf94ca