aave-v3-plugin
Warn
Audited by Socket on May 13, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
Purpose and capabilities are broadly aligned: this is a DeFi/Aave skill that installs a matching CLI and uses it for Aave operations. The main concerns are medium supply-chain exposure from remote installers/binaries, high-risk real-world financial actions, and transitive installation of additional skills that widen trust. No clear credential theft or covert exfiltration is evident, but this should still be treated as a high-risk financial automation skill rather than a benign documentation-only guide.
Confidence: 87%Severity: 78%
Audit Metadata