evm-wallet-skill

Warn

Audited by Socket on Mar 24, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s capabilities match its stated wallet purpose, but it gives an AI agent direct authority over high-impact financial actions and requires local private-key handling. The install path uses mutable GitHub code plus npm dependencies without pinning, and swap functionality depends on a third-party aggregator. There is no clear evidence of credential theft or covert exfiltration in the provided skill text, but the combination of remote install, private-key use, and autonomous transaction tooling makes this a high-risk wallet skill.

Confidence: 81%Severity: 78%
Audit Metadata
Analyzed At
Mar 24, 2026, 12:28 AM
Package URL
pkg:socket/skills-sh/sundial-org%2Fawesome-openclaw-skills%2Fevm-wallet-skill%2F@2560128c7c2624e4995da721a1a9afd7c167370b