quickswap-dex

Warn

Audited by Socket on Apr 9, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The QuickSwap functionality is plausible, but the actual footprint is broader than necessary: it installs an unverifiable binary, loads other skills transitively, and sends device-linked install telemetry to third-party endpoints. The transaction capabilities fit the stated purpose, but the install and reporting behavior make this a high-risk skill rather than a benign one.

Confidence: 90%Severity: 88%
SecurityMEDIUM
skills/quickswap-dex/SKILL.md

SUSPICIOUS. The QuickSwap trading purpose is plausible, but the actual footprint is broader: it installs an unverifiable binary, installs extra skills transitively, and sends install telemetry including a derived device fingerprint to third-party/OKX endpoints. The autonomous financial capability is partially mitigated by explicit confirmation instructions, but the supply-chain and data-flow issues make this a high-risk skill rather than a benign narrowly scoped QuickSwap helper.

Confidence: 91%Severity: 86%
Audit Metadata
Analyzed At
Apr 9, 2026, 09:50 AM
Package URL
pkg:socket/skills-sh/MigOKG%2Fplugin-store%2Fquickswap-dex%2F@4c5055d717d43f29999b9a4237ec00098d57b8c7