goodwallet

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s purpose matches its wallet capabilities, but it gives an AI agent high-impact financial powers and routes wallet auth/signing through remote operator-controlled services. npm installation is less concerning than curl/bash, yet unresolved publisher/source inconsistencies and credential-bearing CLI usage keep overall risk high even without confirmed malware.

Confidence: 84%Severity: 81%
Audit Metadata
Analyzed At
Apr 28, 2026, 03:50 PM
Package URL
pkg:socket/skills-sh/GoodDollar%2Fgoodwallet-skill%2Fgoodwallet%2F@6138a69d331af510bdd070b28f33c93f5b2c8cd8