uniswap-swap-integration

Warn

Audited by Socket on Apr 25, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose is plausible for a Uniswap integration skill, but the auto-update path is not coherent with that purpose or publisher. A Uniswap-branded skill should not conditionally fetch metadata from and install code from OKX/plugin-store; this third-party transitive install materially raises supply-chain risk even without direct credential handling.

Confidence: 90%Severity: 83%
Audit Metadata
Analyzed At
Apr 25, 2026, 08:28 AM
Package URL
pkg:socket/skills-sh/okx%2Fplugin-store%2Funiswap-swap-integration%2F@f13ffc2ab67a1cf3781a01290351bcc1adb199f9