dapp-morpho
Warn
Audited by Socket on Mar 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated Morpho browsing purpose is plausible, but the install path is not coherent with the claimed OKX publisher: it downloads and executes an unpinned installer from a personal GitHub repo, with an unverifiable official fallback. Because the skill also supports private-key-backed on-chain actions, this creates a serious credential-forwarding and supply-chain risk. Treat as high risk until the installer provenance and data flows are verified through an official OKX-owned source.
Confidence: 92%Severity: 90%
Audit Metadata