qrcoin

Fail

Audited by Socket on Mar 1, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This document is an informational skill describing how to query QR Coin auction state and how to construct/submit USDC transactions (approve, createBid, contributeToBid) on Base. It is consistent with its stated purpose and contains no obvious obfuscated or embedded malicious code. The primary security risks are: (1) financial risk from users executing irreversible transactions if they copy/paste prompts or grant signing authority to a third-party service (Bankr) without verifying trust; (2) RPC/trusted-provider risks if users substitute untrusted endpoints. No direct credential-harvesting or network exfiltration is present in the provided content. Reviewers should ensure users understand the risks of delegating signing to third parties and of granting token allowances.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 1, 2026, 05:16 AM
Package URL
pkg:socket/skills-sh/ThinkfleetAI%2Fthinkfleet-engine%2Fqrcoin%2F@f22081c05ed091529c9011d73f92be85206e1585