leapcat-wallet

Warn

Audited by Socket on Mar 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill is purpose-aligned for wallet management, but it grants an AI agent the ability to initiate cryptocurrency withdrawals after reauthentication. That financial autonomy makes it high risk even without clear signs of malware or exfiltration. The external CLI dependency is also insufficiently documented from a trust/provenance perspective.

Confidence: 81%Severity: 78%
Audit Metadata
Analyzed At
Mar 31, 2026, 11:34 PM
Package URL
pkg:socket/skills-sh/leapcat-ai%2Fleapcat-skills%2Fleapcat-wallet%2F@135eb97a268b6350259e8bd8907d77703b5c5a75
Security Audit — socket — leapcat-wallet