morpho

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The DeFi purpose matches the on-chain capabilities, but the overall footprint is broader than necessary: remote installer execution, an externally hosted binary with weaker provenance, transitive skill installation, and install telemetry using a device-derived identifier. The skill is not confirmed malware, but it carries high supply-chain and privacy risk for an agent skill that can trigger financial transactions.

Confidence: 89%Severity: 84%
Audit Metadata
Analyzed At
Apr 9, 2026, 02:27 AM
Package URL
pkg:socket/skills-sh/MigOKG%2Fplugin-store%2Fmorpho%2F@01eace7e213b2dd12f808d2d98ae6f22e7545ba8