zerion-umbra-privateTxn

Warn

Audited by Socket on May 10, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is purpose-aligned and not obviously deceptive, but it enables autonomous cryptocurrency transactions and on-chain retries, giving an AI agent high-impact financial action capability. External doc fetching adds indirect prompt-injection risk, so overall security risk is high despite low evidence of malware.

Confidence: 88%Severity: 81%
Audit Metadata
Analyzed At
May 10, 2026, 07:44 PM
Package URL
pkg:socket/skills-sh/zeriontech%2Fzerion-ai%2Fzerion-umbra-privatetxn%2F@b8f04905df8dd86d2d3e924b7f4f1160e3775c10