vibenet

Warn

Audited by Socket on Sep 11, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s blockchain capabilities and Base-owned API endpoints fit its stated purpose, with no obvious credential harvesting or unrelated file access. Risk comes from supply-chain trust: it asks users to install a transitive skill and use a bundled script to clone/build an unreleased viem fork from a third-party GitHub account, which is proportionate to the task but not fully verifiable from the provided evidence.

Confidence: 87%Severity: 58%
AnomalyLOW
scripts/setup-viem-8130.sh

The script is a legitimate-looking development installer, not overt malware in the provided fragment. It intentionally downloads and executes code from a mutable third-party Git branch and uses unpinned npx/pnpm tooling, while building and installing package lifecycle content. These choices create a meaningful supply-chain risk, especially if run in an environment containing credentials, but there is no direct evidence of data theft, persistence, sabotage, or malicious payload behavior in this file. Pin the repository to a reviewed commit, pin pnpm and dependency versions, verify checksums or signatures, and consider disabling lifecycle scripts during the final npm installation.

Confidence: 96%Severity: 66%
Audit Metadata
Analyzed At
Sep 11, 2026, 06:55 PM
Package URL
pkg:socket/skills-sh/base%2Fskills%2Fvibenet%2F@c020281030253952a4db847e5a14fd446c6ef6559127ff63bb45b2c19c955411
Security Audit — socket — vibenet