compound-v2

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated Compound V2 purpose partially matches the command set, but the skill’s actual footprint is much broader: it installs multiple external skills, pulls an unverifiable binary, and performs install-time telemetry with a derived device fingerprint to third-party endpoints. The DeFi functionality may be real, but the supply-chain and data-flow behavior are disproportionate to a simple Compound helper.

Confidence: 91%Severity: 90%
Audit Metadata
Analyzed At
Apr 9, 2026, 05:46 AM
Package URL
pkg:socket/skills-sh/MigOKG%2Fplugin-store%2Fcompound-v2%2F@c314fc6e77a4784f5749583d150e7ee4e9345e84