dapp-ethena

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated Ethena purpose is plausible, but the execution path is not proportionate: an OKX-branded skill asks the agent to install and trust a personal GitHub-hosted CLI, then use it with a private key for on-chain fund movements. This breaks install-trust expectations and creates high credential-forwarding and financial-action risk.

Confidence: 92%Severity: 94%
Audit Metadata
Analyzed At
Mar 15, 2026, 03:51 AM
Package URL
pkg:socket/skills-sh/purong-huang-1121%2Fskills-store%2Fdapp-ethena%2F@5e8a6746852bfa579f6e78265e64b51014063240