morpho-plugin

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose and data flows mostly align with Morpho lending operations, and the installer sources are plausibly same-org OKX infrastructure rather than random third parties. However, it combines download/execute behavior, transitive skill installation, and autonomous on-chain approval broadcasts with real financial impact, making the operational risk materially higher than a typical documentation or read-only integration skill.

Confidence: 85%Severity: 68%
Audit Metadata
Analyzed At
Apr 28, 2026, 02:14 PM
Package URL
pkg:socket/skills-sh/okx%2Fplugin-store%2Fmorpho-plugin%2F@76541c118858b3c42cb31e53c74b8fb4f923394b