ton-send

Warn

Audited by Socket on Apr 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS due to high-impact autonomous financial capability and reliance on an external MCP backend that may receive wallet credentials, but the behavior is broadly aligned with the stated purpose of sending TON assets. No direct evidence of malicious exfiltration or deceptive routing appears in this skill text; the main concerns are financial-action risk, transitive trust, and credential handling in the TON MCP runtime.

Confidence: 84%Severity: 71%
Audit Metadata
Analyzed At
Apr 14, 2026, 02:40 PM
Package URL
pkg:socket/skills-sh/ton-org%2Fskills%2Fton-send%2F@f7240e9a005e7db96d0f2d52d6b155ad0309aef4