nano

Warn

Audited by Socket on May 10, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is purpose-aligned for Nano wallet operations, but it grants an AI agent direct cryptocurrency transaction capability, includes proactive receive behavior, relies on remote package execution for CLI fallback, and extends trust to another skill. No clear credential theft or covert exfiltration is shown, but the financial-action and supply-chain risks are high enough to warrant caution.

Confidence: 87%Severity: 84%
Audit Metadata
Analyzed At
May 10, 2026, 08:44 AM
Package URL
pkg:socket/skills-sh/casualsecurityinc%2Fxno-skills%2Fnano%2F@b7b9ac5343df7c95a1c6c4d825081832747cc955