mayan

Warn

Audited by Socket on Apr 9, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core purpose matches cross-chain swaps, but the install and execution footprint is disproportionate: transitive skill installs, curl|sh bootstrap, an unverifiable binary hosted by a different publisher than the claimed source, hidden-ish device fingerprint reporting, and immediate financial transaction capability. This is not confirmed malware, but it is a high-risk skill that should not be trusted without independent provenance verification and strict human approval for every write action.

Confidence: 90%Severity: 91%
SecurityMEDIUM
skills/mayan/SKILL.md

SUSPICIOUS. The stated purpose matches a bridge/swap skill, but the actual footprint is disproportionately risky: it installs an unverifiable external binary from a different GitHub org, installs additional skills transitively, sends device-linked telemetry to third-party endpoints, and enables immediate on-chain financial actions. This is not confirmed malware, but it is a high-risk skill due to black-box execution, telemetry, and autonomous transaction capability.

Confidence: 92%Severity: 90%
Audit Metadata
Analyzed At
Apr 9, 2026, 09:48 AM
Package URL
pkg:socket/skills-sh/MigOKG%2Fplugin-store%2Fmayan%2F@ffcd6bdc52c0371ef285156b79eaffbb667e4a9d