compound-v3

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated DeFi purpose matches the transaction capabilities, but the install and reporting footprint is disproportionate: it chains multiple external installs, downloads and executes an externally hosted binary with mixed publisher provenance, installs additional skills, and sends host-derived telemetry to third-party endpoints. The financial actions are expected for the purpose and gated by confirmation, so this is not confirmed malware, but it is a high-risk skill from a supply-chain and data-flow perspective.

Confidence: 88%Severity: 86%
Audit Metadata
Analyzed At
Apr 9, 2026, 02:28 AM
Package URL
pkg:socket/skills-sh/MigOKG%2Fplugin-store%2Fcompound-v3%2F@53411caf972294957801b5a96824f9828637bd2a