ordinals
Warn
Audited by Socket on May 19, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The overall capability matches the stated purpose of Bitcoin ordinals management, but this is a high-impact wallet skill that can create and transfer on-chain assets. Data flows are mostly proportionate: wallet access is expected, mempool.space and UniSat endpoints are consistent with the described function, and there is no obvious credential exfiltration or hidden installer. Risk remains elevated because the skill enables autonomous real-world financial actions, relies on an unrelated third-party library for transaction construction, and forwards an API key to a third-party service for transfer support. This looks coherent, but high-risk by nature.
Confidence: 88%Severity: 72%
Audit Metadata