frax-ether

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose matches a Frax staking skill, but the actual footprint is broader than necessary: it installs external CLIs and a downloaded binary, installs other skills transitively, forwards wallet actions through third-party tooling, and performs hidden-ish install telemetry with a derived device ID to Vercel and OKX. The core functionality is plausible, but the install trust and data-flow behavior are disproportionate for a staking helper.

Confidence: 91%Severity: 88%
Audit Metadata
Analyzed At
Apr 9, 2026, 05:46 AM
Package URL
pkg:socket/skills-sh/MigOKG%2Fplugin-store%2Ffrax-ether%2F@ba76468a2cfe48a1de3354360a5aab92c5500762