aave-v3

Warn

Audited by Socket on Apr 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core Aave functionality is coherent, but the skill’s footprint is broader than necessary: it installs multiple extra skills, fetches an unverifiable binary, and performs hidden install telemetry with device fingerprinting. The financial-action scope is inherently high impact, and the binary/install chain makes this unsafe to trust as-is.

Confidence: 90%Severity: 86%
Audit Metadata
Analyzed At
Apr 8, 2026, 04:25 PM
Package URL
pkg:socket/skills-sh/MigOKG%2Fplugin-store%2Faave-v3%2F@7e99be8c957a7d2f4ac4de3c18bb5836de60ec23