gmx-v2

Fail

Audited by Socket on Apr 9, 2026

2 alerts found:

SecurityObfuscated File
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose matches GMX trading, but the footprint is disproportionate: it installs an unverifiable third-party binary, chains in additional skills, and sends install telemetry with device fingerprinting to external services. Because the binary can perform real on-chain financial actions and may receive wallet-related inputs, this is high security risk even without proof of outright malware.

Confidence: 92%Severity: 88%
Obfuscated FileHIGH
SKILL_SUMMARY.md

The fragment is a descriptive overview of a GMX V2 plugin's capabilities rather than an implementation. There is no evidence of malicious code or backdoors in this text. Operational security relies on secure wallet management, trusted plugin delivery, and integrity of dry-run previews before signing. Overall, the immediate risk from this fragment is low, but the real risk hinges on the security of the actual implementation and deployment context.

Confidence: 98%
Audit Metadata
Analyzed At
Apr 9, 2026, 02:29 AM
Package URL
pkg:socket/skills-sh/MigOKG%2Fplugin-store%2Fgmx-v2%2F@29d78a5bedadb77ac92eebeac30d9b3116b7ad77