fetch-source

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill is coherent with its stated purpose: it fetches contract sources from Sourcify and Etherscan for a given address on a specified chain, with outputs written to a structured local directory. The data flows, credentials (optional API key), and outputs are proportionate and restricted to the intended use. Minor security considerations exist around input sanitization and potential logging of API keys, but there is no evidence of exfiltration, unauthorized autonomy, or unverifiable binaries. Overall, the tool appears benign with moderate security risk if proper input handling and secure logging are not enforced.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 06:56 PM
Package URL
pkg:socket/skills-sh/syjcnss%2Fweb3_skills%2Ffetch-source%2F@99dc86172ec7dcf19faaf764a41730660fd915e1
Security Audit — socket — fetch-source