troves

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill is purpose-aligned and uses an official documented StarkFi npm distribution path, so it does not look malicious. Its main risk is that it grants an AI agent the ability to perform real DeFi deposit/withdraw actions, and it relies on mutable `npx ...@latest` execution, making it high security risk but low malware likelihood.

Confidence: 88%Severity: 76%
Audit Metadata
Analyzed At
Apr 28, 2026, 11:55 AM
Package URL
pkg:socket/skills-sh/ahmetenesdur%2Fstarkfi%2Ftroves%2F@e1583bac46a87b95ba819eff71670afa3cc1f7c4