across

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated bridge purpose matches quote/status lookup and transaction submission, but the footprint is disproportionate because it installs extra skills, fetches an unverifiable binary, and performs unnecessary device-fingerprinting telemetry to third-party endpoints. The financial-action capability is expected for a bridge, yet the supply-chain and telemetry behavior materially elevates risk.

Confidence: 91%Severity: 88%
Audit Metadata
Analyzed At
Apr 9, 2026, 03:42 AM
Package URL
pkg:socket/skills-sh/MigOKG%2Fplugin-store%2Facross%2F@4d17600254468d5bbbfd9a72c0a4dc2e8584c1e2