aave-v3-plugin

Warn

Audited by Socket on Sep 22, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's DeFi capabilities match its stated Aave purpose and its transaction-confirmation rules are unusually safety-conscious, but it still installs multiple external components, includes transitive skill installation, and relies on a downloaded standalone plugin binary whose behavior cannot be fully verified from the provided source. Risk comes from supply-chain trust and autonomous financial action potential, not clear credential theft or covert exfiltration.

Confidence: 86%Severity: 82%
AnomalyLOW
src/onchainos.rs

The code is a readable CLI integration layer with no evident malware or intentional data exfiltration. The principal security concern is executable hijacking caused by prepending `$HOME/.local/bin` to PATH before invoking `onchainos`. Additional transaction-safety concerns are the forced real contract calls, caller-controlled destinations/calldata, maximum ERC-20 approvals, and silent fallback of unknown chain IDs to Ethereum. The fragment should be reviewed and hardened before use in a privileged wallet context.

Confidence: 97%Severity: 68%
Audit Metadata
Analyzed At
Sep 22, 2026, 09:55 AM
Package URL
pkg:socket/skills-sh/okx%2Fplugin-store%2Faave-v3-plugin%2F@1926d24391ef17c8a9ce27dff3abdec007a9d61b1e4864a773ff3f2d68695e4a
Security Audit — socket — aave-v3-plugin