web3-solidity-audit-mcp

Warn

Audited by Socket on Mar 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill’s capabilities largely match its stated smart-contract-audit purpose, but it is a high-risk AI-agent security tool by design. The main concerns are granting an agent exploit-style auditing capabilities, runtime download/execute installation paths, and optional remote SSE mode that can move sensitive contract code off-host. This looks more like a risky but plausibly legitimate security skill than confirmed malware.

Confidence: 84%Severity: 78%
Audit Metadata
Analyzed At
Mar 17, 2026, 04:29 PM
Package URL
pkg:socket/skills-sh/shuvonsec%2Fweb3-bug-bounty-hunting-ai-skills%2Fweb3-solidity-audit-mcp%2F@b1d164f21b22b8d6691db3a618e6012d4afc72ce