arweave

Warn

Audited by Socket on Feb 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This Arweave/ArNS skill is largely coherent: reading a local JWK wallet and contacting Arweave gateways is consistent with its purpose of signing and publishing transactions. The primary risks are operational/privacy: handling of the private JWK (credential exposure), forwarding uploads/keys to third-party Turbo/Irys nodes, and financial risk from spending AR. The documentation addresses many mitigations (local signing, never logging wallet contents, cost estimates, confirmations, dry-run, and prompt-injection cautions). No evidence of obvious malicious code, obfuscated payloads, or download-execute chains is present in the provided text. Overall this skill is plausible and usable for its stated purpose but carries moderate supply-chain and operational risk due to wallet handling and optional third-party upload endpoints; require careful user controls (strict local signing, minimal logging, explicit endpoint choices, and mandatory confirmations for spending) when deploying or granting agent permissions.

Confidence: 80%Severity: 75%
Audit Metadata
Analyzed At
Feb 28, 2026, 09:34 PM
Package URL
pkg:socket/skills-sh/permaweb%2Fskills%2Farweave%2F@8ce4d6c3f2cc0d2abb5d9fc6c991aa14301db14e