nft-manager

Fail

Audited by Socket on Feb 28, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The manifest itself is not directly malicious, but it exposes significant operational risk because it includes state-changing transfer capabilities without describing enforced human confirmation or safe key management. Primary recommendations before trusting an implementation: require explicit interactive human approval for all transfers (deny by default), use an external wallet UI or hardware signing (never accept raw private keys), implement and document ERC721/ERC1155 receiver checks and use safeTransferFrom, validate/whitelist metadata hosts, and audit any third-party tooling/endpoints. Treat any implementation that auto-signs transactions, requests raw private keys, or forwards signing credentials to remote services as high-risk.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 28, 2026, 07:25 AM
Package URL
pkg:socket/skills-sh/TermiX-official%2Fcryptoclaw%2Fnft-manager%2F@519bd5cd0139069d32d8bab18fe53c3b10bf6940