aave

Warn

Audited by Socket on Aug 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is purpose-aligned and mostly uses normal npm/on-chain patterns, with no obvious exfiltration or malware behavior. However, it facilitates irreversible financial actions, handles raw private keys, and includes likely stale/incorrect install guidance for the Aave package, so the operational security risk is medium even though malicious intent is not evident.

Confidence: 88%Severity: 58%
Audit Metadata
Analyzed At
Aug 4, 2026, 12:32 AM
Package URL
pkg:socket/skills-sh/JustaName-id%2Fcryptoskills%2Faave%2F@93b7593a5ce65343f5670c59782e575b766a283bc6fe7945112ca8fc3225c68c
Security Audit — socket — aave