mcp-wallet

Warn

Audited by Socket on Apr 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose matches wallet management, but its actual footprint depends on an unverifiable black-box MCP custody service, can receive mnemonic secrets, permits autonomous cryptocurrency transfers, and may store wallet data in plaintext. The Nano RPC endpoints are plausible, but the unverified custody layer and financial-action capability make the overall risk high.

Confidence: 86%Severity: 84%
Audit Metadata
Analyzed At
Apr 7, 2026, 11:37 AM
Package URL
pkg:socket/skills-sh/casualsecurityinc%2Fxno-skills%2Fmcp-wallet%2F@bb56e56d7bddf14939e51346eba897a95e987a68