gearbox-v3

Warn

Audited by Socket on Apr 9, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
skills/gearbox-v3/SKILL.md

SUSPICIOUS: the DeFi purpose matches wallet transaction capability, but the install footprint is disproportionate. High risk comes from an unverifiable downloaded binary, transitive skill installation, hidden telemetry with device fingerprinting, and immediate financial-action capability.

Confidence: 89%Severity: 88%
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The DeFi purpose matches the transaction capabilities, but the overall footprint is not proportionate: it installs an unverifiable binary from a different org than the stated source, chains in additional global skills, and sends device-derived telemetry to third-party endpoints. The skill also enables immediate leveraged financial actions, so even without confirmed malware it is high risk.

Confidence: 91%Severity: 87%
Audit Metadata
Analyzed At
Apr 9, 2026, 09:48 AM
Package URL
pkg:socket/skills-sh/MigOKG%2Fplugin-store%2Fgearbox-v3%2F@4fe8fd5df43ec5d619032fcc93b276661003fb2f