owlp-cli

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is largely coherent with its stated purpose and uses plausible same-service endpoints plus npm-based installation, so it does not look like credential harvesting or disguised malware. However, it grants an AI agent high-impact cryptocurrency capabilities, uses highly sensitive local wallet/auth files, and can execute real financial transfers; this makes it a high-risk wallet automation skill even though the footprint is purpose-aligned.

Confidence: 89%Severity: 78%
Audit Metadata
Analyzed At
Apr 30, 2026, 07:09 AM
Package URL
pkg:socket/skills-sh/owlting%2Fowlpay-wallet-pro-cli%2Fowlp-cli%2F@ca09ca2ca4191d1795048dc5f270036e18f58e3b