aave

Warn

Audited by Socket on May 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

BENIGN for stated purpose but HIGH RISK in operation: the skill is internally consistent with Aave management on Base and uses the publisher-documented Fibrous CLI path, yet it grants an AI agent the ability to perform real on-chain financial transactions through an unpinned external package. Main concerns are autonomy/financial-action risk and npm supply-chain trust, not evidence of malware or credential theft.

Confidence: 87%Severity: 78%
Audit Metadata
Analyzed At
May 14, 2026, 06:38 AM
Package URL
pkg:socket/skills-sh/ahmetenesdur%2Ffibx-agentic-wallet-skills%2Faave%2F@e615d95cefbc4c32f8f070fa34b50257db162e32
Security Audit — socket — aave