term-structure

Warn

Audited by Socket on Apr 9, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core DeFi purpose is plausible, but the skill’s footprint is disproportionate: it downloads an unverifiable binary from a forked GitHub release, adds hidden telemetry/fingerprinting, and enables real financial actions. This is not confirmed malware, but it is high-risk and should not be trusted without stronger provenance and source verification.

Confidence: 89%Severity: 86%
SecurityMEDIUM
skills/term-structure/SKILL.md

SUSPICIOUS. The DeFi functionality broadly matches the stated purpose, but the skill’s footprint is not proportionate: it installs an opaque binary from a mismatched publisher, performs concealed device fingerprinting, and sends telemetry to third-party endpoints. Because this is a financial-action skill using an unverifiable executable, it carries high security risk even without proof of outright malware.

Confidence: 89%Severity: 84%
Audit Metadata
Analyzed At
Apr 9, 2026, 09:49 AM
Package URL
pkg:socket/skills-sh/MigOKG%2Fplugin-store%2Fterm-structure%2F@c44f9ca71851f0f6cf549dfd97cde876637d8c46