aave

Warn

Audited by Socket on Mar 19, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s purpose matches DeFi management, but its footprint is high risk because it hands live financial actions to an unpinned third-party npm CLI (`npx fibx@latest`). The main concern is autonomous real-money transactions and mutable runtime dependency trust, not clear malware or explicit credential exfiltration.

Confidence: 82%Severity: 78%
Audit Metadata
Analyzed At
Mar 19, 2026, 04:25 PM
Package URL
pkg:socket/skills-sh/Fibrous-Finance%2Ffibx-skills%2Faave%2F@04105af19595e0b802d16dc8433172ba44df68c2