Flagged by auditors
Independent security partners scan this skill's files for malicious content, prompt injection and risky patterns. Verdicts below come from the skills.sh audit program; each partner links to its full report.
Gen Agent Trust Hub
warnThe skill enables autonomous payment authorization and cryptographic signing. While functional for its intended purpose, it requires the AI agent to handle raw Ed25519 private keys within tool parameters, which creates a risk of credential exposure if the agent's context is compromised. Additionally, it lacks sanitization and boundary markers for external data processed during transaction authorization, presenting a surface for indirect prompt injection.
Socket
passNo alerts
Snyk
failRisk: HIGH · No issues
Runlayer
pass1/1 file flagged
ZeroLeaks
passScore: 93/100 · 2 sections analyzed