wallet

Fail

Audited by Socket on Mar 9, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill largely aligns with its stated purpose of displaying wallet balances, but it introduces a command-injection risk via the preprocessing line that interpolates ARGUMENTS into a shell command. There is no evidence of credential handling, external data exfiltration, or autonomous actions. The reliance on an external agentbook binary without verifiable provenance also warrants caution. Overall: SUSPICIOUS due to user-controlled command interpolation; treat as vulnerable pending safer input handling and verified binary provenance.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 9, 2026, 11:16 PM
Package URL
pkg:socket/skills-sh/ardabotai%2Fagentbook%2Fwallet%2F@6bcbee53fd957dff98574b12f3c4dad78b6410c1