sablier-create-vesting

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The stated purpose matches vesting coordination, but the skill explicitly supports agent-run onchain transactions, which are real-world actions with financial impact. The install references point to the same Sablier GitHub org for additional skills, which is coherent, but they rely on a third-party `npx skills` installer and create a transitive trust chain. There is no clear evidence of credential theft, exfiltration, or off-domain API proxying in the provided text, so this is not confirmed malicious; however, the autonomous transaction capability and skill-to-skill installation make it medium/high risk.

Confidence: 90%Severity: 68%
Audit Metadata
Analyzed At
Apr 22, 2026, 11:19 AM
Package URL
pkg:socket/skills-sh/sablier-labs%2Fsablier-skills%2Fsablier-create-vesting%2F@9ef82baafef0c524cd5894772e942ad81b96348c