symbiosis
Audited by Socket on Sep 24, 2026
2 alerts found:
Securityx2SUSPICIOUS: the skill’s purpose matches its capabilities, and its main dependency appears to be an official Bankr CLI, so this is not confirmed malware. However, it authorizes autonomous cryptocurrency transactions, reads a local wallet credential file, routes execution through Bankr APIs, and documents an endpoint that does not cleanly match current official docs; combined with missing script contents, this makes the skill high-risk and only partially verifiable.
This appears to be an intended swap utility, not evident malware. However, it delegates transaction construction to an external quote response and submits transactions without validation or user confirmation; its unlimited token approval makes a malicious or compromised response particularly consequential. Review and constrain the router and spender, and use limited approvals and explicit transaction confirmation.