cobo-agentic-wallet-developer
Warn
Audited by Socket on Apr 23, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s wallet and blockchain capabilities match its stated purpose, but the install path is a major trust problem: it downloads and executes a non-registry CLI from an inconsistent raw GitHub source, then feeds that CLI wallet credentials and enables agent-driven financial actions. Official API endpoints and pact scoping help, but they do not offset the supply-chain and credential-forwarding risk.
Confidence: 86%Severity: 84%
Audit Metadata