goat

Warn

Audited by Socket on Aug 4, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is broadly consistent with an onchain agent toolkit, and its installs are mostly standard registry-based packages, but it grants an AI agent high-impact financial capabilities using raw wallet credentials. The main risk is autonomous asset movement and prompt-driven transaction execution, not clear malware or covert exfiltration.

Confidence: 87%Severity: 82%
AnomalyLOW
templates/goat-agent.ts

No clear indicators of classic supply-chain malware are present in this snippet (no obfuscation, no eval/Function usage, no hidden network exfiltration endpoints, no filesystem/process spawning beyond process exit). The main security concern is authorization/control: the code equips an LLM agent with transaction-capable on-chain tools (ETH and USDC transfer capability) backed by a real signing private key, while relying primarily on natural-language prompting rather than enforcing strict, code-level transaction guardrails before any transfer occurs. Logging tool outputs to stdout may also leak operational details into logs.

Confidence: 62%Severity: 60%
Audit Metadata
Analyzed At
Aug 4, 2026, 12:33 AM
Package URL
pkg:socket/skills-sh/JustaName-id%2Fcryptoskills%2Fgoat%2F@f2f01d66bc21e7ae4d6fb7525b9180d874e9c61a2cafb78a7795d717cff8e9ac
Security Audit — socket — goat