onchain

Warn

Audited by Socket on Apr 3, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s purpose is coherent, and the named upstream services are legitimate for crypto portfolio/tx lookups, but the core `onchain` binary is completely unverifiable from the skill text. Because this opaque CLI is entrusted with Coinbase/Binance secrets and other API keys, the skill carries high supply-chain and credential-forwarding risk even without direct evidence of malicious intent.

Confidence: 88%Severity: 84%
Audit Metadata
Analyzed At
Apr 3, 2026, 07:39 PM
Package URL
pkg:socket/skills-sh/sundial-org%2Fawesome-openclaw-skills%2Fonchain%2F@b65edfb68625d29fe6045b4570f9ce184c451142