building-secure-contracts
Audited by Socket on May 6, 2026
2 alerts found:
AnomalySecuritySUSPICIOUS. The skill’s stated purpose, capabilities, and data access are largely consistent with a Cairo/StarkNet auditing guide, and it does not seek credentials or exfiltrate data. However, its installation instructions are materially inconsistent with the official Caracal project and could lead users to install an unrelated PyPI package, making this a medium supply-chain risk despite otherwise coherent behavior.
SUSPICIOUS: the skill is purpose-aligned and appears to come from legitimate Trail of Bits sources, with no clear credential theft or covert exfiltration. However, it equips an AI agent with contract vulnerability scanning/offensive security functionality and relies on transitive remote installation, making it a high-risk vulnerable skill rather than confirmed malware.