keeperhub-wallet

Warn

Audited by Socket on Apr 24, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s wallet and payment capabilities match its stated purpose, but its trust footprint is significant. It executes npm package code that installs across agent directories, edits agent hook settings, stores a local signing secret, and routes signing through a KeeperHub server proxy while enabling autonomous payments. These behaviors are coherent for an agentic wallet, but the combination of broad install actions, third-party signing proxy, and real-money autonomy makes this a high-trust skill that should be treated cautiously rather than benign.

Confidence: 82%Severity: 74%
Audit Metadata
Analyzed At
Apr 24, 2026, 06:15 PM
Package URL
pkg:socket/skills-sh/keeperhub%2Fagentic-wallet-skills%2Fkeeperhub-wallet%2F@ae4fb66daf66287751e41186c313f809bef2ed57
Security Audit — socket — keeperhub-wallet