morpho-base

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated Morpho/Base lending purpose is plausible, but the actual footprint is broader than necessary. The main issues are an unverifiable downloaded binary, transitive installation of extra skills, and install telemetry that fingerprints the device and posts to a Vercel endpoint unrelated to core Morpho functionality. User-confirmation rules reduce direct abuse risk, but overall install trust and data-flow integrity are weak.

Confidence: 91%Severity: 88%
Audit Metadata
Analyzed At
Apr 9, 2026, 02:27 AM
Package URL
pkg:socket/skills-sh/MigOKG%2Fplugin-store%2Fmorpho-base%2F@802949dc2e7271e295200caee78c56cdb837887c