multi-swap

Warn

Audited by Socket on Apr 5, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose matches batch token swaps, but it enables autonomous financial transactions and depends on an unpinned external npm CLI executed via npx. No clear credential-harvesting or exfiltration behavior is shown, so this looks more like a high-risk transaction skill than confirmed malware.

Confidence: 83%Severity: 79%
Audit Metadata
Analyzed At
Apr 5, 2026, 10:15 AM
Package URL
pkg:socket/skills-sh/ahmetenesdur%2Fstarkfi%2Fmulti-swap%2F@aa31327f96504af1828c2d0340286fa5f9f8a16a