ton-cli

Warn

Audited by Socket on Apr 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is coherent with its stated TON wallet purpose and appears to use an official TON-distributed npm package, so it is not clearly malicious. However, it enables direct financial actions, handles wallet secrets, and relies on `npx` execution of a mutable `@alpha` package, making the overall risk medium-to-high even with user-confirmation guidance.

Confidence: 86%Severity: 68%
Audit Metadata
Analyzed At
Apr 14, 2026, 02:40 PM
Package URL
pkg:socket/skills-sh/ton-org%2Fskills%2Fton-cli%2F@00ff52bc22286bf3a1ce16b57bdde5b55d57d596