compose-compliance-oracle
Warn
Audited by Socket on Aug 28, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core behavior mostly matches the stated purpose of building a compliance-gated Compose app, and the main network/data flows go to official Goldsky and Webacy endpoints. However, the skill has a broad real-world action footprint (wallets, contract deployment, contract writes, optional private key use), includes raw remote installers, and instructs transitive skill loading, so its operational risk is medium even without clear malicious intent.
Confidence: 90%Severity: 63%
Audit Metadata