lienfi

Warn

Audited by Socket on Sep 24, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill is internally coherent and uses official same-org endpoints with no installer or proxy abuse, so it does not look like credential theft or malware. But it gives an AI agent authority to sign and submit real financial transactions from a wallet, requires high-privilege wallet access, and relies on manual bearer handoff, making it a high-impact autonomous-action skill even with otherwise legitimate data flows.

Confidence: 92%Severity: 76%
AnomalyLOW
catalog.json

No direct malicious behavior is evident in this declarative fragment. It does, however, instruct users to grant significant wallet capabilities and share a bearer authorization credential, and it references external code that is not included for review. Verify the skill implementation and restrict wallet permissions and approvals before use.

Confidence: 94%Severity: 62%
Audit Metadata
Analyzed At
Sep 24, 2026, 04:47 AM
Package URL
pkg:socket/skills-sh/bankrbot%2Fskills%2Flienfi%2F@7f5e1ccf724dbb91faf381d648f35bc1cf72ad48cad7fb58ac7ee0149fce28f3
Security Audit — socket — lienfi