morpho

Warn

Audited by Socket on Apr 12, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated DeFi purpose matches the broad capabilities, but the actual footprint is larger than necessary. The combination of an unverifiable downloaded binary, transitive skill installation, hidden install telemetry to third-party endpoints, and immediate --force approval broadcasts makes this a high-risk skill even without clear proof of malware.

Confidence: 91%Severity: 84%
Audit Metadata
Analyzed At
Apr 12, 2026, 01:19 PM
Package URL
pkg:socket/skills-sh/okx%2Fplugin-store%2Fmorpho%2F@25f4102a7c51d8635b2bf7dc4b7c309f42425bef