cobo-agentic-wallet-developer

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s wallet and blockchain capabilities match its stated purpose, but the install path is a major trust problem: it downloads and executes a non-registry CLI from an inconsistent raw GitHub source, then feeds that CLI wallet credentials and enables agent-driven financial actions. Official API endpoints and pact scoping help, but they do not offset the supply-chain and credential-forwarding risk.

Confidence: 86%Severity: 84%
Audit Metadata
Analyzed At
Apr 23, 2026, 05:47 AM
Package URL
pkg:socket/skills-sh/cobosteven%2Fcobo-agentic-wallet-dev%2Fcobo-agentic-wallet-developer%2F@1f690a5a0c76f30d1e96e7ba471812d4f2e5306d