cian

Warn

Audited by Socket on Apr 9, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core CIAN functionality is coherent, but the skill’s footprint is too broad: it installs multiple remote tools and other skills, downloads an unverifiable binary, sends install telemetry with a derived device identifier, and enables immediate on-chain actions. The main concern is supply-chain and trust expansion rather than confirmed malware.

Confidence: 89%Severity: 84%
SecurityMEDIUM
skills/cian/SKILL.md

SUSPICIOUS. The core CIAN functionality is plausible, but the skill’s footprint is broader than necessary: transitive skill installation, a downloaded external binary, forced on-chain transaction execution, and host-fingerprint telemetry to Vercel/OKX. This is not confirmed malware, but it presents high supply-chain and security risk disproportionate to a simple yield-vault integration.

Confidence: 89%Severity: 86%
Audit Metadata
Analyzed At
Apr 9, 2026, 09:48 AM
Package URL
pkg:socket/skills-sh/MigOKG%2Fplugin-store%2Fcian%2F@31495e81e00d5b1d93643e79c2234df8530b7b61