Swarmwage Hire
PassAudited by VirusTotal on May 13, 2026.
Findings (1)
The skill facilitates autonomous crypto payments by requiring a raw Ethereum private key (SWARMWAGE_PRIVATE_KEY) and installing a remote package via 'npx -y @swarmwage/mcp'. While the instructions in SKILL.md include budget awareness and failure handling, the requirement for a plaintext private key and the execution of third-party code for financial transactions represent high-risk behaviors. There is no explicit evidence of malicious intent in the provided files, but the architecture creates a significant attack surface for credential theft or unauthorized fund depletion.
