hermetica-yield-rotator

Warn

Audited by Socket on May 2, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is coherent for a DeFi yield rotator and the MCP install path appears publisher-consistent, so this is not clear malware or credential theft. However, it enables autonomous real-world financial actions, is non-user-invocable, depends on an external unpinned MCP package, and can output commands that move funds; that makes it high security risk even though its purpose and data flows are largely consistent.

Confidence: 86%Severity: 78%
Audit Metadata
Analyzed At
May 2, 2026, 10:58 AM
Package URL
pkg:socket/skills-sh/aibtcdev%2Fskills%2Fhermetica-yield-rotator%2F@c74c117d3009ddb6d0bbfec7fae979a7a1204c8e