uniswap-ai

Warn

Audited by Socket on Apr 25, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s stated purpose is a Uniswap tool, but its update mechanism delegates trust to OKX’s plugin-store and performs transitive global skill installation. This is not confirmed malware, but the publisher mismatch and unpinned remote update path make the install chain higher risk than a normal same-org skill.

Confidence: 91%Severity: 72%
Audit Metadata
Analyzed At
Apr 25, 2026, 08:27 AM
Package URL
pkg:socket/skills-sh/okx%2Fplugin-store%2Funiswap-ai%2F@32448badbbcb863efb0f95fb479608b89eb908e5