multi-swap
Warn
Audited by Socket on Mar 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated purpose matches trading behavior, but the skill delegates wallet-connected financial actions to an unverified `npx` package using `@latest`, with no confirmed official Fibrous distribution path. That combination makes the capability high risk and disproportionate for autonomous use, even without proof of explicit malware.
Confidence: 83%Severity: 82%
Audit Metadata