exactly-protocol

Warn

Audited by Socket on Apr 9, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core Exactly lending/borrowing functionality matches the stated purpose, but the skill’s footprint is broader than necessary: it installs a separately distributed binary from a different publisher path, chains into additional skills, and phones home install telemetry including a device-derived ID to Vercel and OKX. The financial transaction capability is expected for a DeFi skill, yet the unverifiable binary distribution and unrelated reporting make the overall package medium-high risk rather than benign.

Confidence: 91%Severity: 83%
SecurityMEDIUM
skills/exactly-protocol/SKILL.md

SUSPICIOUS. The lending/borrowing purpose is plausible, but the skill’s footprint is broader than necessary: it installs multiple external skills, downloads an unverifiable binary, performs hidden-ish install telemetry with device fingerprinting, and enables high-impact financial actions. The on-chain functionality fits the stated purpose, but the install chain and reporting behavior materially raise trust and security concerns.

Confidence: 90%Severity: 88%
Audit Metadata
Analyzed At
Apr 9, 2026, 09:48 AM
Package URL
pkg:socket/skills-sh/MigOKG%2Fplugin-store%2Fexactly-protocol%2F@5acd1f890d76f6e1331dcbd2df080e0118871d4e