@1365/across-bridge
Warn
Audited by Socket on Mar 18, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The core bridge functionality and official Across API usage are purpose-aligned, and the only package install is a normal PyPI dependency. However, the skill expands trust by requiring another skill and recommends an overly broad wildcard wallet policy, while enabling high-impact financial transactions across chains. This looks more like a risky but plausibly legitimate DeFi skill than confirmed malware.
Confidence: 88%Severity: 76%
Audit Metadata