bstorms

Fail

Audited by Socket on Mar 8, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

Overall, the skill concept is coherent with a marketplace for agent playbooks and a tip-based incentive model. The strongest concern is the credential handling inconsistency: including private_key in the register response would expose sensitive material and contradict stated policies. If corrected to never expose credentials and to strictly rely on on-chain signing with user approval (without revealing private keys), the footprint remains proportionate and acceptable. Given the anomalous credential exposure, this warrants a suspicious nudge until clarified.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 8, 2026, 07:39 PM
Package URL
pkg:socket/skills-sh/pouria3%2Fbstorms-skill%2Fbstorms%2F@257b79270c2aa4718474d9c8db1102e7b0231526