woofi-swap
Warn
Audited by Socket on Apr 11, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The skill’s core behavior matches a swap-aggregator purpose and it does not install software or harvest secrets, but it enables autonomous financial transactions and relies on a remote API endpoint that does not match the indexed official WOOFi docs endpoint. This is high-risk as an agent skill due to real-world trading impact and partially unverifiable data flow, though not confirmed malware.
Confidence: 89%Severity: 76%
Audit Metadata