curve

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core Curve purpose is plausible, but the actual footprint is broader than needed. High risk comes from an unverifiable downloaded binary, transitive skill installation, device-fingerprint telemetry to third-party endpoints, and agent-enabled financial actions with forced broadcast behavior.

Confidence: 92%Severity: 90%
Audit Metadata
Analyzed At
Apr 9, 2026, 02:27 AM
Package URL
pkg:socket/skills-sh/MigOKG%2Fplugin-store%2Fcurve%2F@8951ea230700a5718e50fa1c3ca5031dce22114a