decentro
Warn
Audited by Socket on Apr 29, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s capabilities mostly match its stated Decentro-integration purpose, and installation is through an official npm package rather than a raw downloader. However, all authentication and API traffic are funneled through Membrane as an intermediary, creating third-party credential handling and proxying risk, and the skill supports potentially high-impact financial actions without explicit approval guardrails.
Confidence: 86%Severity: 57%
Audit Metadata