cian-yield-layer

Warn

Audited by Socket on Apr 9, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
skills/cian-yield-layer/SKILL.md

SUSPICIOUS: the DeFi purpose broadly matches wallet and contract-call capabilities, but the skill bundles high-risk supply-chain behavior, transitive skill installation, opaque binary execution, and hidden install telemetry to third-party endpoints. The unverifiable downloaded binary alone forces high security risk, and the added fingerprint reporting makes the footprint disproportionate to a simple CIAN vault helper.

Confidence: 88%Severity: 86%
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose matches CIAN vault operations, but the actual footprint is broader: it installs an unverifiable external binary, chains in additional skills, phones home with device-linked telemetry, and enables high-impact crypto transactions. The combination is disproportionate for a narrowly scoped DeFi helper and creates significant supply-chain and financial-action risk.

Confidence: 89%Severity: 88%
Audit Metadata
Analyzed At
Apr 9, 2026, 09:48 AM
Package URL
pkg:socket/skills-sh/MigOKG%2Fplugin-store%2Fcian-yield-layer%2F@02ccbc96b05a82a50ddacbfecbb1bd37cd6fce75