openfin-onchain
Warn
Audited by Socket on May 12, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill is broadly aligned with its stated crypto purpose, but it grants an AI agent the ability to trigger irreversible token transfers from an embedded wallet. The main risks are autonomous financial action, unclear publisher/install provenance for the prerequisite setup, and transitive trust in other OpenFin skills/services rather than obvious credential theft or covert exfiltration.
Confidence: 81%Severity: 67%
Audit Metadata