dapp-ethena
Warn
Audited by Socket on Mar 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated Ethena purpose is plausible, but the execution path is not proportionate: an OKX-branded skill asks the agent to install and trust a personal GitHub-hosted CLI, then use it with a private key for on-chain fund movements. This breaks install-trust expectations and creates high credential-forwarding and financial-action risk.
Confidence: 92%Severity: 94%
Audit Metadata