pp-defillama
Warn
Audited by Socket on Aug 18, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill's stated read-only DefiLlama purpose is mostly coherent, but its install and execution model relies on third-party Printing Press binaries from a personal repo and diverges from DefiLlama's official MCP setup. No direct credential harvesting is present, but the supply-chain trust mismatch and optional webhook output make this higher risk than a normal documentation or API skill.
Confidence: 86%Severity: 74%
Audit Metadata