building-secure-contracts

Warn

Audited by Socket on May 6, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
skills/cairo-vulnerability-scanner/SKILL.md

SUSPICIOUS. The skill’s stated purpose, capabilities, and data access are largely consistent with a Cairo/StarkNet auditing guide, and it does not seek credentials or exfiltrate data. However, its installation instructions are materially inconsistent with the official Caracal project and could lead users to install an unrelated PyPI package, making this a medium supply-chain risk despite otherwise coherent behavior.

Confidence: 90%Severity: 56%
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is purpose-aligned and appears to come from legitimate Trail of Bits sources, with no clear credential theft or covert exfiltration. However, it equips an AI agent with contract vulnerability scanning/offensive security functionality and relies on transitive remote installation, making it a high-risk vulnerable skill rather than confirmed malware.

Confidence: 82%Severity: 74%
Audit Metadata
Analyzed At
May 6, 2026, 02:11 PM
Package URL
pkg:socket/skills-sh/jswortz%2Fmy-skills%2Fbuilding-secure-contracts%2F@52b5f7b4b9e41b120d02beac1276dff24ce2b9df
Security Audit — socket — building-secure-contracts