allium-onchain-data
Warn
Audited by Socket on Mar 21, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core API usage and official Allium data flows fit the stated blockchain analytics purpose, so this is not fundamentally malicious. However, the skill materially expands scope by reading/writing raw credentials from ~/.allium/credentials, using an undocumented-looking register-v2 polling flow, and autonomously saving API keys after background polling without a second confirmation. These are moderate credential-handling and trust concerns, but there is no evidence of third-party credential routing or clear exfiltration.
Confidence: 88%Severity: 52%
Audit Metadata