lienfi
Audited by Socket on Sep 24, 2026
2 alerts found:
SecurityAnomalySUSPICIOUS: The skill is internally coherent and uses official same-org endpoints with no installer or proxy abuse, so it does not look like credential theft or malware. But it gives an AI agent authority to sign and submit real financial transactions from a wallet, requires high-privilege wallet access, and relies on manual bearer handoff, making it a high-impact autonomous-action skill even with otherwise legitimate data flows.
No direct malicious behavior is evident in this declarative fragment. It does, however, instruct users to grant significant wallet capabilities and share a bearer authorization credential, and it references external code that is not included for review. Verify the skill implementation and restrict wallet permissions and approvals before use.