yield-agentkit-privy

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill is coherent with its stated purpose, but that purpose is inherently high risk: it installs a remote MCP, ingests external content, and can autonomously move funds through Privy-signed blockchain transactions. Data flows mostly match official Yield/Privy services rather than obvious exfiltration infrastructure, so this is not confirmed malware, but it is a high-risk financial automation skill.

Confidence: 87%Severity: 84%
Audit Metadata
Analyzed At
Apr 28, 2026, 07:37 AM
Package URL
pkg:socket/skills-sh/stakekit%2Fagentkit%2Fyield-agentkit-privy%2F@a34e71d4ddcfd9e38e67abcb56847ad763f1602e