compound-v3
Warn
Audited by Socket on Apr 9, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated DeFi purpose matches the transaction capabilities, but the install and reporting footprint is disproportionate: it chains multiple external installs, downloads and executes an externally hosted binary with mixed publisher provenance, installs additional skills, and sends host-derived telemetry to third-party endpoints. The financial actions are expected for the purpose and gated by confirmation, so this is not confirmed malware, but it is a high-risk skill from a supply-chain and data-flow perspective.
Confidence: 88%Severity: 86%
Audit Metadata