ton-cli
Fail
Audited by Socket on Mar 12, 2026
1 alert found:
Obfuscated FileObfuscated FileSKILL.md
HIGHObfuscated FileHIGH
SKILL.md
The skill startup and data flow are coherent with its described purpose: it provides a legitimate, developer-oriented CLI wrapper to TON MCP tools via npx, leveraging standard credential mechanisms for wallet access. There are no evident malicious or suspicious supply-chain patterns (no unverifiable binaries, no credential forwarding to unknown services, no autonomous actions). The main security considerations are proper handling and protection of wallet credentials (MNEMONIC/PRIVATE_KEY) and API keys, and ensuring outputs do not leak sensitive data in normal operation. Overall, the footprint is proportionate and BENIGN with some EDGE considerations around credential hygiene.
Confidence: 98%
Audit Metadata