morpho-plugin
Audited by Socket on Sep 29, 2026
2 alerts found:
SecurityAnomalySUSPICIOUS. The skill is purpose-aligned for Morpho lending, and its endpoints/install sources are mostly coherent with official OKX infrastructure, so this is not confirmed malware. But it has a large trust footprint: multiple downloaded executables/scripts, transitive skill installation, and blockchain write capability with immediate approval broadcasts, making the overall security risk high and disproportionate for routine agent use.
The code implements a vault supply operation and shows no clear malware or data-exfiltration behavior. A significant confirmation-flow defect allows an ETH-to-WETH transaction to occur before the user passes the --confirm gate. Validate token and vault addresses and ensure dry-run helpers do not submit transactions.