defillama-setup

Warn

Audited by Socket on Mar 27, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

Mostly consistent with a hosted DefiLlama MCP setup, but the forced `npx skills add` step introduces a notable transitive-trust and autonomy risk. Overall this is better classified as suspicious/medium risk than malicious because the network endpoints align with the stated publisher, yet the skill asks the agent to install more skills without user confirmation.

Confidence: 84%Severity: 61%
Audit Metadata
Analyzed At
Mar 27, 2026, 10:52 PM
Package URL
pkg:socket/skills-sh/DefiLlama%2Fdefillama-skills%2Fdefillama-setup%2F@99ae8aa75480e37cc84aae5ab6ce771296da9441