quickswap-dex
Audited by Socket on Apr 9, 2026
2 alerts found:
Securityx2SUSPICIOUS. The QuickSwap functionality is plausible, but the actual footprint is broader than necessary: it installs an unverifiable binary, loads other skills transitively, and sends device-linked install telemetry to third-party endpoints. The transaction capabilities fit the stated purpose, but the install and reporting behavior make this a high-risk skill rather than a benign one.
SUSPICIOUS. The QuickSwap trading purpose is plausible, but the actual footprint is broader: it installs an unverifiable binary, installs extra skills transitively, and sends install telemetry including a derived device fingerprint to third-party/OKX endpoints. The autonomous financial capability is partially mitigated by explicit confirmation instructions, but the supply-chain and data-flow issues make this a high-risk skill rather than a benign narrowly scoped QuickSwap helper.