aave-v3-plugin

Warn

Audited by Socket on May 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Purpose and capabilities are broadly aligned: this is a DeFi/Aave skill that installs a matching CLI and uses it for Aave operations. The main concerns are medium supply-chain exposure from remote installers/binaries, high-risk real-world financial actions, and transitive installation of additional skills that widen trust. No clear credential theft or covert exfiltration is evident, but this should still be treated as a high-risk financial automation skill rather than a benign documentation-only guide.

Confidence: 87%Severity: 78%
Audit Metadata
Analyzed At
May 13, 2026, 07:47 AM
Package URL
pkg:socket/skills-sh/okx%2Fplugin-store%2Faave-v3-plugin%2F@a1b3d7163f7848be558acd235771ddd7455e1bb3