rehype

Warn

Audited by Socket on Feb 25, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill is an operational runbook for administering an on-chain Rehype Doppler hook. The content itself does not contain obfuscated code, remote download-execute instructions, or embedded malware. However, it documents workflows that require high-privilege signers and broadcasting signed transactions to RPC endpoints, which are inherently high-risk operations in the software supply chain and for funds custody. The main risks are credential exposure (privileged keys), misuse of privileged operations (fee redirection, misconfiguration), and untrusted RPC providers seeing signed payloads. These risks are expected for an administrative deployment/testing skill but warrant mitigation: enforce signer best practices (hardware wallets or isolated CI with minimal scopes), prefer multisig/governance for critical actions, audit deployment scripts before broadcast, and use trusted RPC endpoints.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 25, 2026, 02:38 AM
Package URL
pkg:socket/skills-sh/rustydotwtf%2Fdoppler-skills%2Frehype%2F@55b02eb6a462d15a2e7901b2d2768a5c475c4d20