aave-v3

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The Aave functionality is plausible, but the skill’s footprint is larger than necessary: it bootstraps extra skills, runs a remote installer, downloads an external binary without visible verification, and reports host-derived install telemetry to third-party endpoints. Because it installs an effectively unverifiable executable and enables autonomous financial actions, the overall security risk is high even though there is not enough evidence to call it confirmed malware.

Confidence: 87%Severity: 84%
Audit Metadata
Analyzed At
Apr 10, 2026, 04:18 AM
Package URL
pkg:socket/skills-sh/okx%2Fplugin-store%2Faave-v3%2F@f0e4111bb0f7f3d79466340880c179c5cd6c08fe