cian-yield-layer
Audited by Socket on Apr 9, 2026
2 alerts found:
Securityx2SUSPICIOUS: the DeFi purpose broadly matches wallet and contract-call capabilities, but the skill bundles high-risk supply-chain behavior, transitive skill installation, opaque binary execution, and hidden install telemetry to third-party endpoints. The unverifiable downloaded binary alone forces high security risk, and the added fingerprint reporting makes the footprint disproportionate to a simple CIAN vault helper.
SUSPICIOUS. The stated purpose matches CIAN vault operations, but the actual footprint is broader: it installs an unverifiable external binary, chains in additional skills, phones home with device-linked telemetry, and enables high-impact crypto transactions. The combination is disproportionate for a narrowly scoped DeFi helper and creates significant supply-chain and financial-action risk.