pancakeswap-v2

Warn

Audited by Socket on Apr 12, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core PancakeSwap trading purpose matches the declared functionality, but the skill has a high-risk execution footprint: curl|sh bootstrap, transitive skill installation, downloaded binary execution, and outbound install telemetry to a Vercel endpoint plus OKX. Financial transaction capability is expected for this skill, and the explicit confirmation requirements are a meaningful safeguard, but the extra installation and reporting flows are broader than necessary.

Confidence: 84%Severity: 78%
Audit Metadata
Analyzed At
Apr 12, 2026, 01:19 PM
Package URL
pkg:socket/skills-sh/okx%2Fplugin-store%2Fpancakeswap-v2%2F@3ea1baffbe5e3d6a65bf5588f7bfa4d97ad34681