moonwell

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The DeFi purpose broadly matches the Moonwell commands, but the skill’s footprint is disproportionate: it installs an unverifiable binary, chains in extra skills, and performs hidden install telemetry with device fingerprinting to third-party endpoints. Financial actions are expected for this domain, but the install and data-flow model is not minimally scoped or fully trustworthy.

Confidence: 91%Severity: 89%
Audit Metadata
Analyzed At
Apr 9, 2026, 05:46 AM
Package URL
pkg:socket/skills-sh/MigOKG%2Fplugin-store%2Fmoonwell%2F@03d7f9396e4ccd4b68f8e02f073086ef5b0477bf