gmx-v2-plugin

Warn

Audited by Socket on Apr 25, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill is broadly aligned with its stated GMX trading purpose and data flows are mostly proportionate, but it carries medium security risk because it installs remote code, pulls a binary/launcher from GitHub releases, installs other skills transitively, and can execute real financial transactions. This looks more like a high-impact trading plugin with supply-chain and operational risk than malware.

Confidence: 86%Severity: 66%
Audit Metadata
Analyzed At
Apr 25, 2026, 08:28 AM
Package URL
pkg:socket/skills-sh/okx%2Fplugin-store%2Fgmx-v2-plugin%2F@fa096591f22aa32972b0f2a85ca138be934849d4