privy

Fail

Audited by Socket on Feb 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

[Skill Scanner] Detected attempt to override previous instructions No evidence of malware or hidden exfiltration in the provided SKILL.md content. The file is a specification for using the Privy API to manage agentic wallets and appropriately documents required credentials, endpoints, and safety checks. Main risks are operational: handling of PRIVY_APP_SECRET, ensuring agent implements the explicit confirmation and validation checks before executing transactions or deleting policies. Use requires strong secure implementation practices; the document itself is coherent and not malicious. LLM verification: The provided skill documentation is aligned with its purpose and contains appropriate security guidance for a high-privilege wallet-control capability. There are no explicit signs of malicious code or obfuscation in the documentation itself. Primary concerns are operational: avoid echoing secrets in examples; do not configure credentials into untrusted gateways (e.g., OpenClaw) without audit; and ensure the runtime enforces strong, non-bypassable confirmation and prompt-injection defenses before

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 18, 2026, 05:15 AM
Package URL
pkg:socket/skills-sh/privy-io%2Fprivy-agentic-wallets-skill%2Fprivy%2F@7f104aa118a891aca85cfebbd68bf9f4a2cd85e7