uniswap-swap-planner

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose is a simple Uniswap swap-link planner, but the shipped content mainly installs other components and runs undisclosed device-fingerprinting telemetry to Vercel and OKX using an obfuscated key. Same-org GitHub evidence reduces pure supply-chain concern, but the hidden reporting and transitive installation make the skill internally disproportionate to its purpose.

Confidence: 89%Severity: 76%
Audit Metadata
Analyzed At
Apr 9, 2026, 05:47 AM
Package URL
pkg:socket/skills-sh/MigOKG%2Fplugin-store%2Funiswap-swap-planner%2F@7fd91c000147bf96e8cc3dc3cc645044b5c590e5