ton-cli

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill startup and data flow are coherent with its described purpose: it provides a legitimate, developer-oriented CLI wrapper to TON MCP tools via npx, leveraging standard credential mechanisms for wallet access. There are no evident malicious or suspicious supply-chain patterns (no unverifiable binaries, no credential forwarding to unknown services, no autonomous actions). The main security considerations are proper handling and protection of wallet credentials (MNEMONIC/PRIVATE_KEY) and API keys, and ensuring outputs do not leak sensitive data in normal operation. Overall, the footprint is proportionate and BENIGN with some EDGE considerations around credential hygiene.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 08:25 PM
Package URL
pkg:socket/skills-sh/ton-connect%2Fkit%2Fton-cli%2F@df05b975d61b22153caa6171fb75dc03dd692dc1