uniswap-v4-security-foundations

Warn

Audited by Socket on Apr 25, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The visible footprint is not well aligned with a passive Uniswap security guide: most of the behavior is remote update and transitive skill/plugin installation. The strongest concern is the trust mismatch between Uniswap Labs branding and the auto-update path through okx/plugin-store, which raises supply-chain and transitive-trust risk even though there is no clear credential theft or confirmed malware.

Confidence: 87%Severity: 72%
Audit Metadata
Analyzed At
Apr 25, 2026, 08:29 AM
Package URL
pkg:socket/skills-sh/okx%2Fplugin-store%2Funiswap-v4-security-foundations%2F@a9a97eb96bae4265c9b382bd1803d7fdaedfa6ad