aerodrome-amm

Warn

Audited by Socket on Apr 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The DEX functionality broadly matches the stated purpose, but the skill relies on an unverifiable downloaded binary, installs additional skills transitively, performs hidden install telemetry with a device fingerprint, and enables high-impact financial actions. The main concern is supply-chain trust and unnecessary outbound reporting rather than confirmed credential theft.

Confidence: 88%Severity: 84%
Audit Metadata
Analyzed At
Apr 8, 2026, 03:14 PM
Package URL
pkg:socket/skills-sh/MigOKG%2Fplugin-store%2Faerodrome-amm%2F@3fac7c6eafc86fa335019c73ed08331a2c35112c