hyperliquid-plugin
Audited by Socket on Sep 29, 2026
3 alerts found:
Anomalyx3SUSPICIOUS. The skill’s trading and wallet capabilities broadly match its stated purpose, and its data flows mostly target expected OKX/onchainos and Hyperliquid endpoints. However, it has a larger-than-usual footprint: it installs multiple external components, pulls and executes same-org remote scripts, installs other skills transitively, and enables autonomous financial actions under an autotrade path. These are coherent with a live-trading plugin but elevate security risk well above a normal documentation skill.
The fragment is a readable wallet and Hyperliquid transaction integration module, not apparent malware. It intentionally invokes an external CLI capable of signing and submitting financial operations. The configurable executable path and limited local validation create meaningful supply-chain and transaction-integrity risks, but no direct malicious behavior is demonstrated in this code. The onchainos binary should be authenticated or pinned, and callers should validate addresses, amounts, chain IDs, typed data, and all high-impact actions before signing.
The fragment appears to be legitimate blockchain bridging functionality, not malware. It performs external network requests and can cause real wallet transactions, but those actions are consistent with its stated purpose. The main security risk is insufficient validation of relay.link-controlled transaction destinations and calldata before signing approval or deposit transactions. Amount handling should also explicitly reject non-finite and excessively large values. Review the relay service trust model and add strict transaction validation before enabling production use.