dapp-uniswap

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose matches Uniswap trading, but the execution path is not proportionate or trustworthy: an OKX-branded skill installs and updates a wallet-signing CLI from an unrelated personal GitHub repo via curl|sh, then exposes EVM_PRIVATE_KEY to that external tool. This creates a high supply-chain and credential-theft risk, plus autonomous financial-action risk.

Confidence: 94%Severity: 94%
Audit Metadata
Analyzed At
Mar 15, 2026, 03:51 AM
Package URL
pkg:socket/skills-sh/purong-huang-1121%2Fskills-store%2Fdapp-uniswap%2F@98f95bd6562ac378a885973afc3d406e94745aef