zerion

Warn

Audited by Socket on Apr 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill's overall purpose fits crypto wallet operations, but the official-evidence mismatch on package name and repository materially weakens install trust. Because the skill asks for API keys and private keys and enables financial actions through an external CLI, the provenance inconsistency makes the risk high even without proof of confirmed malware.

Confidence: 89%Severity: 82%
Audit Metadata
Analyzed At
Apr 27, 2026, 10:03 AM
Package URL
pkg:socket/skills-sh/zeriontech%2Fzerion-agent%2Fzerion%2F@c27471613308fd27d2ef8de595f798dab5792e71