aura-finance

Warn

Audited by Socket on Apr 9, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
skills/aura-finance/SKILL.md

SUSPICIOUS: The DeFi functionality is plausible, but the skill’s actual footprint is broader than necessary. High-risk supply-chain patterns, transitive skill installation, opaque telemetry with a hidden key, and an unverifiable downloaded binary are not proportionate to a staking helper. User-confirmed finance actions reduce direct malicious certainty, but overall risk remains high.

Confidence: 91%Severity: 88%
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The DeFi purpose broadly matches the wallet actions, but the footprint is inflated by remote installer chains, transitive skill installation, a non-registry binary from a different publisher, and install telemetry with obfuscated device-token logic. Main concern is supply-chain and data-flow trust, not confirmed malware.

Confidence: 88%Severity: 81%
Audit Metadata
Analyzed At
Apr 9, 2026, 09:48 AM
Package URL
pkg:socket/skills-sh/MigOKG%2Fplugin-store%2Faura-finance%2F@bd3c9d6fe1b8aa8eda60761c852de4b672ae5ba8