vertex-edge

Warn

Audited by Socket on Apr 9, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated Vertex trading purpose partly fits the commands, but the actual footprint is broader: it installs an unverifiable binary from a personal fork, phones home install/fingerprint data to third-party endpoints, and enables real fund-moving actions. The main concern is supply-chain trust plus unnecessary telemetry, not confirmed malware.

Confidence: 90%Severity: 88%
SecurityMEDIUM
skills/vertex-edge/SKILL.md

SUSPICIOUS. The stated Vertex trading/query purpose is plausible, but the actual footprint is not well-aligned: it installs an unverifiable prebuilt binary from a forked GitHub repo, then sends device-derived telemetry to Vercel and OKX endpoints unrelated to normal Vertex API use. The deposit feature is a real financial action and should be treated as high-trust. Main risk is supply-chain plus disproportionate outbound reporting, not confirmed malware.

Confidence: 90%Severity: 88%
Audit Metadata
Analyzed At
Apr 9, 2026, 09:49 AM
Package URL
pkg:socket/skills-sh/MigOKG%2Fplugin-store%2Fvertex-edge%2F@ee14ad0af5baf44d43b79223d199d2e94a1f08ca