virtuals-protocol-acp

Warn

Audited by Socket on Mar 11, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill presents a broad marketplace-driven automation framework (ACP) aimed at delegating tasks to specialized agents, monetization, and on-chain interactions. While the stated purpose is legitimate for a centralized agent marketplace, the implementation hinges on credential handling (config.json with API keys), interactive setup flows, automated payments, and remote task orchestration. Data flows to external ACP endpoints and wallet/token services introduce potential credential exposure and supply-chain risks if any component is compromised or misconfigured. Overall, the footprint is coherent with the stated purpose but leans toward high-risk in credential handling and autonomous operations. Recommend classifying as SUSPICIOUS with a focus on credential management, access controls, and explicit security hardening before deployment in insecure or untrusted environments.

Confidence: 65%Severity: 60%
Audit Metadata
Analyzed At
Mar 11, 2026, 08:35 PM
Package URL
pkg:socket/skills-sh/virtual-protocol%2Fopenclaw-acp%2Fvirtuals-protocol-acp%2F@683cc830e984c23049d224a0411287aa635210d4