soma

Warn

Audited by Socket on May 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill is purpose-aligned and mostly coherent with its SOMA-network role, but it is still high risk because it enables autonomous blockchain reward actions, handles multiple sensitive credentials, pushes secrets to Modal, and uses a raw remote installer. This is better classified as suspicious/high-risk rather than malicious: the footprint fits the claimed purpose, but the trust and financial-action surface are substantial.

Confidence: 90%Severity: 81%
Audit Metadata
Analyzed At
May 4, 2026, 03:03 PM
Package URL
pkg:socket/skills-sh/soma-org%2Fskills%2Fsoma%2F@ee59d0a45b4989c506d8580994ecd873c93a0b92