thespawn

Warn

Audited by Socket on May 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core purpose is internally coherent for a web3 agent-registry skill, but the trust model is weakened by transitive skill installation, runtime `npx` execution of external tooling, and support for autonomous onchain/public actions. No clear credential theft or hidden exfiltration is visible from the provided content, so this is better classified as high-risk/vulnerable rather than confirmed malicious.

Confidence: 81%Severity: 72%
Audit Metadata
Analyzed At
May 1, 2026, 03:45 PM
Package URL
pkg:socket/skills-sh/thespawnio%2Fskill%2Fthespawn%2F@557e54edeb19b859baa0675004c108ff4580da6e
Security Audit — socket — thespawn