etherfi

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated ether.fi staking purpose partly matches the on-chain reads/writes, but the actual footprint is larger and riskier: it installs an unverifiable third-party binary, installs additional skills, and sends install telemetry with a device-derived identifier to external endpoints using concealed key material. The crypto-transaction capability is inherently high impact, and the nonessential reporting behavior is not proportionate to a protocol helper skill.

Confidence: 88%Severity: 86%
Audit Metadata
Analyzed At
Apr 9, 2026, 02:36 AM
Package URL
pkg:socket/skills-sh/MigOKG%2Fplugin-store%2Fetherfi%2F@200b7bea4bb151b5d97c6506a3b9e0f2ffea12bd