TRC20 Token Toolkit

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s capabilities match its stated TRC20 purpose and its dependency/install story is mostly coherent, but it gives an AI agent the ability to perform irreversible token transfers and approvals using a raw private key. That makes it high-impact even without clear malware indicators; risk comes from autonomous financial action and key handling, not from deceptive data flows.

Confidence: 87%Severity: 71%
Audit Metadata
Analyzed At
Apr 10, 2026, 07:06 AM
Package URL
pkg:socket/skills-sh/BofAI%2Fskills%2Ftrc20-token-toolkit%2F@b0ea72576b499ea39c36ec11bae7222da65d12fa