jito
Warn
Audited by Socket on Apr 9, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated DeFi purpose matches some capabilities, but the actual footprint is much broader: it installs multiple external skills, fetches an unverifiable binary from a third-party GitHub release, performs device fingerprint reporting to third-party endpoints, and enables financial transactions. The telemetry and distribution path are not proportionate to a simple Jito staking skill, so this should be treated as high-risk vulnerable content rather than benign documentation.
Confidence: 94%Severity: 91%
Audit Metadata