phantom-wallet-mcp

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

BENIGN for stated purpose but HIGH RISK in operation. The skill is internally consistent with a Phantom wallet integration and appears to use Phantom-owned infrastructure, but it enables autonomous financial transactions, persistent wallet sessions, and unpinned npx execution, so it should only be used with explicit per-action approval and low-value test wallets.

Confidence: 82%Severity: 74%
Audit Metadata
Analyzed At
Mar 15, 2026, 06:39 PM
Package URL
pkg:socket/skills-sh/sendaifun%2Fskills%2Fphantom-wallet-mcp%2F@826a6480d3079d1ed6301886fe336da0f8c56e30