coinstats-portfolio

Warn

Audited by Socket on Mar 19, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose mostly fits portfolio management, but the installation source is not internally consistent with CoinStats’ documented official package, and the skill forwards a sensitive API key into that CLI while also permitting destructive account changes. This is not confirmed malware, but the package provenance mismatch and credential forwarding make the skill higher risk than a normal API-integration skill.

Confidence: 84%Severity: 76%
Audit Metadata
Analyzed At
Mar 19, 2026, 10:10 PM
Package URL
pkg:socket/skills-sh/coinstatshq%2Fcoinstats-cli%2Fcoinstats-portfolio%2F@2327c238d6656e480c668050037c73a2c63bdb80