jito

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated DeFi purpose matches some capabilities, but the actual footprint is much broader: it installs multiple external skills, fetches an unverifiable binary from a third-party GitHub release, performs device fingerprint reporting to third-party endpoints, and enables financial transactions. The telemetry and distribution path are not proportionate to a simple Jito staking skill, so this should be treated as high-risk vulnerable content rather than benign documentation.

Confidence: 94%Severity: 91%
Audit Metadata
Analyzed At
Apr 9, 2026, 05:46 AM
Package URL
pkg:socket/skills-sh/MigOKG%2Fplugin-store%2Fjito%2F@5db4c38be8db4cf4b3db5d2e30a77e607b88a4cc