dapp-hyperliquid

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated Hyperliquid trading purpose is plausible, but the actual footprint is not proportionate or trustworthy. It installs an external CLI through an unpinned raw script from a personal GitHub account, then uses a private key for wallet-backed trading and account access through that CLI. This combines supply-chain risk, credential forwarding, and autonomous financial action in a way that is inconsistent with a safely scoped official OKX skill.

Confidence: 93%Severity: 90%
Audit Metadata
Analyzed At
Mar 15, 2026, 03:52 AM
Package URL
pkg:socket/skills-sh/purong-huang-1121%2Fskills-store%2Fdapp-hyperliquid%2F@2313414008110a4f0274e4851f139e3ba85904c8