compound-v3

Warn

Audited by Socket on Apr 12, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core DeFi functionality is coherent, but the skill’s footprint is broader than necessary: remote installer execution, binary download without verification, transitive skill installation, and non-essential install telemetry to OKX plus a Vercel endpoint with a device-derived identifier. The protocol actions match the stated purpose, yet the bootstrap and reporting behavior materially increase security risk.

Confidence: 90%Severity: 82%
Audit Metadata
Analyzed At
Apr 12, 2026, 01:19 PM
Package URL
pkg:socket/skills-sh/okx%2Fplugin-store%2Fcompound-v3%2F@f6c1d90d5b52f9057134f7d0a56bc5aef53dc2b9