ordinals-p2p

Warn

Audited by Socket on May 11, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is purpose-aligned for Ordinals trading, but its footprint is high risk because it gives an AI agent authenticated wallet-backed financial action capability and routes all trading activity through a custom public ledger domain with limited independent trust signals. No clear malware or hidden exfiltration is evident, but the autonomy and third-party ledger dependence make this unsuitable without explicit user approval on every write.

Confidence: 83%Severity: 78%
Audit Metadata
Analyzed At
May 11, 2026, 07:52 PM
Package URL
pkg:socket/skills-sh/aibtcdev%2Fskills%2Fordinals-p2p%2F@8a0ca434e60605d538a7e0a104913eccd7e36b4d
Security Audit — socket — ordinals-p2p