venice-auth

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s overall purpose and data flows mostly align with Venice authentication, and requests go directly to official Venice endpoints. The main risk is the unverified npm SDK name combined with forwarding a raw wallet private key into that package, plus optional USDC top-up actions; this is proportionate to the x402 feature set but raises medium security risk.

Confidence: 85%Severity: 52%
Audit Metadata
Analyzed At
Apr 23, 2026, 08:04 PM
Package URL
pkg:socket/skills-sh/veniceai%2Fskills%2Fvenice-auth%2F@0ee1ffd46455e31617030b2308e2f3c50b0972ad