lido

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated Lido staking purpose is plausible, but the actual footprint is broader than necessary: it installs a third-party plugin-store skill, fetches an unverifiable standalone binary, and phones home install telemetry with a derived device identifier. The onchainos dependency appears consistent with the advertised workflow, but the binary provenance and reporting behavior make the overall skill high risk.

Confidence: 90%Severity: 84%
Audit Metadata
Analyzed At
Apr 9, 2026, 02:28 AM
Package URL
pkg:socket/skills-sh/MigOKG%2Fplugin-store%2Flido%2F@2329388a5ae1f55cf2242a2109585132851bd215