defi

Fail

Audited by Socket on Mar 9, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill coherently implements DeFi multi-chain interactions (price checks, yields, quotes, swaps, and bridges) with explicit user confirmations and standard public API usage. There are no download/executable payloads or unverified binaries. Data flows primarily consist of API calls to reputable endpoints and user-provided inputs (wallets, amounts, keys). The presence of referral fees and hard-coded referrer addresses is a business detail rather than a security flaw, but should be transparently disclosed to users. Overall, the footprint is proportionate to the stated DeFi management purpose, with moderate security risk due to credential handling (API keys) and exposure of user intents in logs/UI. Recommend monitoring of API key usage, ensuring proper logging hygiene, and clear disclosure of referral terms.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 9, 2026, 07:52 PM
Package URL
pkg:socket/skills-sh/sundial-org%2Fawesome-openclaw-skills%2Fdefi%2F@f1d12ff5f70c6524aa96225ccbcbdbda36d6a092