1inch-mcp-server

Warn

Audited by Socket on Apr 27, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is largely purpose-aligned and points to official 1inch infrastructure, so it is not overtly malicious. Risk comes from two factors: real-world financial actions (swaps/orders) and the optional third-party `supergateway` bridge installed via `npx`, which may handle API credentials during stdio proxying.

Confidence: 88%Severity: 68%
Audit Metadata
Analyzed At
Apr 27, 2026, 03:53 PM
Package URL
pkg:socket/skills-sh/1inch%2F1inch-ai%2F1inch-mcp-server%2F@4dc601b333912ea9fbf39ae6a091de5378c38cd2