curve-plugin

Warn

Audited by Socket on May 12, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md
AnomalyLOW
plugin.yaml

No direct malicious payload or obfuscation is evident from this fragment because it is only a manifest/config. The main security concern is that the declared network endpoints include atypical plugin-management/install and wallet plugin download/report URLs in addition to normal Curve/RPC endpoints. This raises supply-chain risk that should be validated by reviewing the Rust implementation for network-driven install/update behavior, integrity checks, and any execution/storage of downloaded content.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
May 12, 2026, 10:59 AM
Package URL
pkg:socket/skills-sh/okx%2Fplugin-store%2Fcurve-plugin%2F@d112c9c1f565030c6f2b808b4eddcdc050fe49c9