instadapp

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The blockchain functionality broadly matches the stated Instadapp purpose, but the skill’s footprint is disproportionate because it installs an unverifiable external binary, installs other skills transitively, and phones home install telemetry with a device-derived identifier. The real-world transaction capability is expected for a DeFi skill, yet the install and data-flow patterns materially raise risk beyond a normal read/write vault integration.

Confidence: 90%Severity: 82%
Audit Metadata
Analyzed At
Apr 9, 2026, 05:46 AM
Package URL
pkg:socket/skills-sh/MigOKG%2Fplugin-store%2Finstadapp%2F@6965904ab55cd5fd132849193c13d9cbcc43c69f