zkvm-evaluator

Warn

Audited by Socket on Mar 30, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is purpose-aligned for zkVM-based job evaluation, and the backend installers appear to be official same-org sources, but its footprint is still high risk because it executes client-supplied binaries and can autonomously perform on-chain fund-releasing settlement. This is not confirmed malware, but it enables dangerous real-world actions and untrusted code execution.

Confidence: 86%Severity: 82%
Audit Metadata
Analyzed At
Mar 30, 2026, 12:16 AM
Package URL
pkg:socket/skills-sh/termix-official%2Fcryptoclaw%2Fzkvm-evaluator%2F@1dd4b4b0e89ee8ae81251c9464242faa301c30f7