air-agentic-wallet

Warn

Audited by Socket on Mar 25, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is purpose-aligned for agentic wallet control, but it enables autonomous financial/onchain actions and sends signing material to a runtime-provided AIR endpoint that is not pinned to a clearly verified official domain. No malware or installer abuse is evident, but the combination of high-impact actions and endpoint trust ambiguity makes the overall security risk high.

Confidence: 86%Severity: 78%
Audit Metadata
Analyzed At
Mar 25, 2026, 02:31 AM
Package URL
pkg:socket/skills-sh/MocaNetwork%2Fair-agentic-wallet-skill%2Fair-agentic-wallet%2F@1a6e3668b3190ddb5ddfa1608d28f1fd0b4be006