ton-send
Warn
Audited by Socket on Apr 14, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS due to high-impact autonomous financial capability and reliance on an external MCP backend that may receive wallet credentials, but the behavior is broadly aligned with the stated purpose of sending TON assets. No direct evidence of malicious exfiltration or deceptive routing appears in this skill text; the main concerns are financial-action risk, transitive trust, and credential handling in the TON MCP runtime.
Confidence: 84%Severity: 71%
Audit Metadata