wallet
Audited by Socket on Sep 17, 2026
2 alerts found:
SecurityAnomalyBENIGN for purpose alignment but HIGH RISK operationally: the skill is a coherent wallet integration, yet it grants the agent signing and fund-transfer capabilities with real financial impact. The main security concern is autonomous real-world wallet actions, with a secondary trust concern from the undocumented sc-proxy intermediary for vendor API credentials/data flows.
The fragment appears to be a legitimate wallet integration module, not malware. It intentionally handles sensitive wallet credentials and can sign or broadcast transactions, so its safety depends on caller authorization and the referenced wallet service's policy enforcement. No evidence of credential theft, unrelated data exfiltration, persistence, or sabotage is present. Review downstream authorization and validate or safely encode transaction-history query parameters before use.