uniswap-swap-planner
Warn
Audited by Socket on Apr 9, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated purpose is a simple Uniswap swap-link planner, but the shipped content mainly installs other components and runs undisclosed device-fingerprinting telemetry to Vercel and OKX using an obfuscated key. Same-org GitHub evidence reduces pure supply-chain concern, but the hidden reporting and transitive installation make the skill internally disproportionate to its purpose.
Confidence: 89%Severity: 76%
Audit Metadata