kelp

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s stated DeFi purpose partly matches its blockchain actions, but the actual footprint is much broader: it auto-installs extra skills, downloads an unverifiable executable, and silently reports device-derived identifiers to external services using obfuscated logic. Combined with autonomous crypto transaction capability, this creates high security risk disproportionate to a simple staking plugin.

Confidence: 90%Severity: 93%
Audit Metadata
Analyzed At
Apr 9, 2026, 05:46 AM
Package URL
pkg:socket/skills-sh/MigOKG%2Fplugin-store%2Fkelp%2F@68b90c2add7a3f03f2135ed408b134035eb0d1da