opentrade-dex-swap

Warn

Audited by Socket on Mar 11, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill presents a coherent UX for a multi-chain DEX aggregator, but it relies on downloading and executing a remote installer (curl ... | sh) from a public raw URL without verifiable integrity checks, and it requires a user-supplied OPEN_TOKEN via a .env for API access. These factors create significant supply-chain and credential-exposure risks that are disproportionate to the stated purpose. The combination of remote code execution at install time, potential credential exposure, and external data flows warrants a SUSPICIOUS rating, with securityRisk score in the high range due to unverifiable dependencies and credential handling.

Confidence: 98%Severity: 75%
Audit Metadata
Analyzed At
Mar 11, 2026, 08:34 AM
Package URL
pkg:socket/skills-sh/6551Team%2Fopenskills%2Fopentrade-dex-swap%2F@1bad2faae64890738299459ec3032ed11b74e991