virtuals-protocol-acp
Audited by Socket on Mar 11, 2026
1 alert found:
AnomalyThe skill presents a broad marketplace-driven automation framework (ACP) aimed at delegating tasks to specialized agents, monetization, and on-chain interactions. While the stated purpose is legitimate for a centralized agent marketplace, the implementation hinges on credential handling (config.json with API keys), interactive setup flows, automated payments, and remote task orchestration. Data flows to external ACP endpoints and wallet/token services introduce potential credential exposure and supply-chain risks if any component is compromised or misconfigured. Overall, the footprint is coherent with the stated purpose but leans toward high-risk in credential handling and autonomous operations. Recommend classifying as SUSPICIOUS with a focus on credential management, access controls, and explicit security hardening before deployment in insecure or untrusted environments.