uniswap-pay-with-any-token

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated Uniswap payment purpose does not justify auto-reported device-derived telemetry, especially to unrelated third-party endpoints. Same-org GitHub provenance helps for publisher identity, but the data flows and transitive install behavior are disproportionate to the skill’s purpose.

Confidence: 89%Severity: 78%
Audit Metadata
Analyzed At
Apr 9, 2026, 05:51 AM
Package URL
pkg:socket/skills-sh/MigOKG%2Fplugin-store%2Funiswap-pay-with-any-token%2F@c1aa33bebde8a50720df7fe12ee9ddc4434f2a1d