executing-agw-transactions
Warn
Audited by Socket on Mar 24, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The skill’s stated purpose matches blockchain signing and execution tasks, and its preview-first discipline is safety-oriented. However, it relies on an `agw` CLI whose official provenance was not verified in the supplied evidence, while official AGW documentation instead points to same-org SDK/npm tooling. That unverifiable executable dependency creates a high supply-chain risk, though there is no clear evidence of credential harvesting, stealth, or malicious exfiltration.
Confidence: 86%Severity: 72%
Audit Metadata