camelot-v3
Warn
Audited by Socket on Apr 9, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the stated DeFi purpose matches the trading features, but the overall footprint is disproportionate. It combines remote install-and-execute behavior, an unverifiable plugin binary, transitive skill installation, device telemetry to third-party endpoints, and AI-enabled financial actions. The onchainos installer has some official same-org evidence, but the camelot-v3 binary and reporting flow keep the skill in high-risk territory.
Confidence: 90%Severity: 87%
Audit Metadata