pendle

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The trading purpose broadly matches the described commands, but the footprint is larger than necessary: it installs third-party skills, downloads an unverifiable binary, and sends device-linked install telemetry to external services. The financial-action capability is expected for a Pendle plugin, yet the supply-chain and telemetry behavior make this a high-risk skill rather than a benign narrowly scoped integration.

Confidence: 89%Severity: 87%
Audit Metadata
Analyzed At
Apr 9, 2026, 02:27 AM
Package URL
pkg:socket/skills-sh/MigOKG%2Fplugin-store%2Fpendle%2F@9f5a451938222f67835db082c8109b811a806590