wallet

Warn

Audited by Socket on Sep 17, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md

BENIGN for purpose alignment but HIGH RISK operationally: the skill is a coherent wallet integration, yet it grants the agent signing and fund-transfer capabilities with real financial impact. The main security concern is autonomous real-world wallet actions, with a secondary trust concern from the undocumented sc-proxy intermediary for vendor API credentials/data flows.

Confidence: 84%Severity: 78%
AnomalyLOW
wallet.py

The fragment appears to be a legitimate wallet integration module, not malware. It intentionally handles sensitive wallet credentials and can sign or broadcast transactions, so its safety depends on caller authorization and the referenced wallet service's policy enforcement. No evidence of credential theft, unrelated data exfiltration, persistence, or sabotage is present. Review downstream authorization and validate or safely encode transaction-history query parameters before use.

Confidence: 97%Severity: 58%
Audit Metadata
Analyzed At
Sep 17, 2026, 04:30 AM
Package URL
pkg:socket/skills-sh/starchild-ai-agent%2Fofficial-skills%2Fwallet%2F@037c3010f930b551da9a74873301d16bbfbc0d25952418e8567a46d7fd258bfd
Security Audit — socket — wallet