four-meme

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose fits DeFi trading, but the actual footprint is broader than necessary: it installs an unverifiable third-party binary, installs additional skills transitively, and performs hidden install telemetry with device fingerprinting to a Vercel endpoint and OKX. The official OKX onchainos installer appears legitimate, but the plugin-store and four-meme distribution chain is not proportionate or clearly attributable to the claimed skill publisher.

Confidence: 91%Severity: 88%
Audit Metadata
Analyzed At
Apr 9, 2026, 05:46 AM
Package URL
pkg:socket/skills-sh/MigOKG%2Fplugin-store%2Ffour-meme%2F@56ad7df58b9fe501059def07bf3c289d669179b6