uniswap-pay-with-any-token

Warn

Audited by Socket on Apr 25, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose is plausible, but this file's main behavior is transitive installation and self-update from remote sources, including a mutable OKX-hosted plugin-store path despite Uniswap authorship claims. The install/update footprint is broader and less verifiable than necessary for a simple payment helper, though there is not enough evidence here to call it confirmed malware.

Confidence: 85%Severity: 74%
Audit Metadata
Analyzed At
Apr 25, 2026, 08:28 AM
Package URL
pkg:socket/skills-sh/okx%2Fplugin-store%2Funiswap-pay-with-any-token%2F@27c5bfaa24966d1a0099639b9c610b8a90e41dcb