cli-cast

Warn

Audited by Socket on Apr 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s capabilities mostly match its stated purpose, but it is high risk because it enables autonomous on-chain signing and transaction submission, handles raw private keys, defaults to a third-party RPC gateway, and includes transitive skill installation guidance. This looks like a coherent blockchain-operation skill, not confirmed malware, but its permission and consequence footprint is inherently dangerous.

Confidence: 90%Severity: 78%
Audit Metadata
Analyzed At
Apr 20, 2026, 04:42 PM
Package URL
pkg:socket/skills-sh/PaulRBerg%2Fagent-skills%2Fcli-cast%2F@dfa7053a59efff2fa5535e9bac60a855c69f666f