compose-vrf

Warn

Audited by Socket on Aug 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core VRF/deployment behavior is consistent with the stated purpose, and crypto/on-chain functionality belongs in this skill, but it carries meaningful operational risk because it installs or loads additional tooling/skills and can autonomously deploy apps and submit blockchain transactions. Data flows are mostly coherent and official, so this looks more like a high-impact deployment skill than credential-harvesting malware.

Confidence: 88%Severity: 58%
Audit Metadata
Analyzed At
Aug 1, 2026, 07:05 PM
Package URL
pkg:socket/skills-sh/goldsky-io%2Fgoldsky-agent%2Fcompose-vrf%2F@c77a45560639ff755681b9a45c1e3a6feea519ce901fc7eb424f27c5590aab05
Security Audit — socket — compose-vrf