Web3 Yield Automator
PassAudited by VirusTotal on May 10, 2026.
Findings (1)
The bundle is a functional stub that lacks the DeFi automation logic described in SKILL.md, which claims to be a $299 'premium' tool. It is classified as suspicious because the instructions direct the user to install an external global NPM package (web3-yield-automator) to access features, a common vector for supply-chain or social engineering attacks. While the provided index.js only manages a local config.json and contains no inherently malicious code, the overall package acts as a lure for external execution and lacks the implementation of its stated purpose.
