erc-8004

Fail

Audited by Socket on Mar 7, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill description is largely coherent with ERC-8004's trustless-agent model and the Agent0 SDK workflow. It reasonably covers on-chain identities, reputation, and endpoint discovery, with off-chain registration data and IPFS usage as expected. However, there are security-related gaps around credentials handling in the examples (private keys, RPC URLs, PINATA JWT) and a lack of explicit secure data validation/verification for off-chain registration data. These gaps warrant caution: credentials in samples should be clearly marked as placeholders, with strong guidance for secure storage and rotation. Overall, the footprint is proportionate to the stated purpose, but the risk posture is non-trivial due to credential exposure and external data dependencies; treat as SUSPICIOUS to BENIGN depending on how securely the implementation handles secrets and validates on/off-chain data.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 7, 2026, 06:00 AM
Package URL
pkg:socket/skills-sh/tenequm%2Fclaude-plugins%2Ferc-8004%2F@f24e58918e7b978c64d2b763360716d6aad46d4b