openfin-relay

Warn

Audited by Socket on May 12, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's capabilities match its stated crypto bridging purpose, but it enables high-impact financial actions and routes execution through an OpenFinance intermediary rather than Relay's direct official API surface. There is no malware-like installer behavior, but the delegated signing/execution model, third-party backend routing, and support for external recipients/arbitrary bridge+call targets make this a high-risk financial automation skill.

Confidence: 86%Severity: 76%
Audit Metadata
Analyzed At
May 12, 2026, 08:00 PM
Package URL
pkg:socket/skills-sh/openfinance-tech%2Fskills%2Fopenfin-relay%2F@53ce5e1be865c087b38458048aa93abc96a2602b
Security Audit — socket — openfin-relay