senpi-getting-started-guide

Fail

Audited by Socket on Feb 28, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The fragment presents a coherent, purpose-aligned onboarding flow for first trades but introduces notable security and supply-chain risk vectors: unpinned remote code installation, local state file handling with potential exposure, and lack of explicit authentication/validation for MCP interactions. Recommend tightening security with: pinned versions and integrity checks for all installations, code signing or hash verification for downloaded SKILL.md/assets, explicit MCP authentication/authorization requirements, least-privilege access to local state files, and redacting or safeguarding wallet addresses in user messages. If possible, replace shell-based onboarding guidance with a guarded, authenticated initialization process and remove reliance on local state manipulation from downstream workflows.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 28, 2026, 07:25 PM
Package URL
pkg:socket/skills-sh/Senpi-ai%2Fsenpi-skills%2Fsenpi-getting-started-guide%2F@9d017f406658199eaef44850ab66b7291ab004ec