File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- SKILL.md:130
Security audit
Security checks across malware telemetry and agentic risk
This is a clearly disclosed Ethereum agent-wallet skill with real financial risk, but its high-impact behavior is purpose-aligned and includes explicit user-approval boundaries.
Install only if you are comfortable giving an agent-facing wallet access to real funds. Keep the seed phrase, PIN, and keyring password outside agent-controlled terminals, consider setting RUSTOK_MCP_CAPABILITIES to read-only or preview-only for lower-trust agents, and treat sign_message as sensitive because it is not separately console-approved.
1/64 vendors flagged this skill as malicious, and 63/64 flagged it as clean.
Detected: suspicious.exposed_secret_literal