soma
Warn
Audited by Socket on May 4, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The skill is purpose-aligned and mostly coherent with its SOMA-network role, but it is still high risk because it enables autonomous blockchain reward actions, handles multiple sensitive credentials, pushes secrets to Modal, and uses a raw remote installer. This is better classified as suspicious/high-risk rather than malicious: the footprint fits the claimed purpose, but the trust and financial-action surface are substantial.
Confidence: 90%Severity: 81%
Audit Metadata