ordinals

Warn

Audited by Socket on May 19, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The overall capability matches the stated purpose of Bitcoin ordinals management, but this is a high-impact wallet skill that can create and transfer on-chain assets. Data flows are mostly proportionate: wallet access is expected, mempool.space and UniSat endpoints are consistent with the described function, and there is no obvious credential exfiltration or hidden installer. Risk remains elevated because the skill enables autonomous real-world financial actions, relies on an unrelated third-party library for transaction construction, and forwards an API key to a third-party service for transfer support. This looks coherent, but high-risk by nature.

Confidence: 88%Severity: 72%
Audit Metadata
Analyzed At
May 19, 2026, 06:26 PM
Package URL
pkg:socket/skills-sh/aibtcdev%2Fskills%2Fordinals%2F@be2fbac9d58dd072bd003cef30fd0981bd908743
Security Audit — socket — ordinals