vibenet
Audited by Socket on Sep 11, 2026
2 alerts found:
Anomalyx2SUSPICIOUS: the skill’s blockchain capabilities and Base-owned API endpoints fit its stated purpose, with no obvious credential harvesting or unrelated file access. Risk comes from supply-chain trust: it asks users to install a transitive skill and use a bundled script to clone/build an unreleased viem fork from a third-party GitHub account, which is proportionate to the task but not fully verifiable from the provided evidence.
The script is a legitimate-looking development installer, not overt malware in the provided fragment. It intentionally downloads and executes code from a mutable third-party Git branch and uses unpinned npx/pnpm tooling, while building and installing package lifecycle content. These choices create a meaningful supply-chain risk, especially if run in an environment containing credentials, but there is no direct evidence of data theft, persistence, sabotage, or malicious payload behavior in this file. Pin the repository to a reviewed commit, pin pnpm and dependency versions, verify checksums or signatures, and consider disabling lifecycle scripts during the final npm installation.