zyfai

Warn

Audited by Socket on Mar 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is coherent with its DeFi-yield purpose and uses official-looking npm and Zyfai endpoints, so it is not confirmed malware. However, it enables autonomous financial transactions, requires wallet signing capability plus an API key, and forwards those capabilities into a third-party SDK/backend, making the overall security risk high despite reasonable purpose alignment.

Confidence: 84%Severity: 78%
Audit Metadata
Analyzed At
Mar 31, 2026, 06:23 AM
Package URL
pkg:socket/skills-sh/BankrBot%2Fskills%2Fzyfai%2F@8dcfee9a2c2677aa19fa6d0fae3d82b0e22c2909