blockrun
Warn
Audited by Socket on Jul 28, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is purpose-aligned, but its footprint is high risk because it enables autonomous spending, stores/uses local wallet authority, and routes user data through a third-party payment gateway to external models. The PyPI install path looks plausible and same-org, so this is not confirmed malware, but the financial autonomy and intermediary data flow make the skill dangerous.
Confidence: 84%Severity: 78%
Audit Metadata