skale-sfuel-skill

Warn

Audited by Socket on Apr 4, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
scripts/mine_sfuel.py

This code is a minimal entrypoint that executes skale.utils.sfuel.mine_sfuel immediately when run. The wrapper itself shows no direct malicious operations, but the function name and immediate execution pattern are strong indicators consistent with cryptomining/compute abuse. Since the mine_sfuel implementation is not provided, malicious intent (e.g., network exfiltration, persistence, or process spawning) cannot be confirmed from this fragment alone; the primary risk is unauthorized CPU/network activity. Recommend inspecting skale/utils/sfuel.py for evidence of mining pools/stratum traffic, persistence mechanisms, subprocess usage, and any outbound network endpoints or file/process modifications.

Confidence: 42%Severity: 66%
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose broadly matches its capability, but it can trigger on-chain actions, contemplates private-key env vars, and withholds the actual helper code and dependency list. The main risk is incomplete trust verification rather than confirmed malicious behavior.

Confidence: 81%Severity: 62%
Audit Metadata
Analyzed At
Apr 4, 2026, 06:26 AM
Package URL
pkg:socket/skills-sh/skalenetwork%2Fskale-skills%2Fskale-sfuel-skill%2F@8cd896146768ed5e02ea186fc628b20c310dec7e