okx-buildx-hackathon-agent-track

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core hackathon workflow is plausible, but the actual footprint is broader than needed: raw-script install, transitive third-party skill installation, hidden install telemetry to a Vercel endpoint, and support for autonomous public/on-chain actions. The telemetry and extra plugin-store trust chain are the main reasons this is not benign.

Confidence: 89%Severity: 84%
Audit Metadata
Analyzed At
Apr 9, 2026, 05:46 AM
Package URL
pkg:socket/skills-sh/MigOKG%2Fplugin-store%2Fokx-buildx-hackathon-agent-track%2F@2b25008e81ed4a36532899a2efb5f93551629427