aave

Warn

Audited by Socket on Sep 17, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The capability fits the stated DeFi purpose, but it performs high-impact financial actions and depends on an undisclosed external wallet service/runtime. With no install malware signals or obvious exfiltration in the visible skill, the main risk is unverifiable transaction routing and autonomous asset movement rather than confirmed malicious intent.

Confidence: 82%Severity: 76%
AnomalyLOW
_trade_report.py

The code implements opt-in-looking telemetry/reporting controlled by environment variables, but it sends trade events and CONTAINER_JWT to any configured endpoint without enforcing HTTPS or host allowlisting. This could enable data or credential disclosure if the environment is misconfigured or compromised. No clear malicious payload, hardcoded exfiltration destination, or other malware behavior is evident in this fragment.

Confidence: 97%Severity: 58%
Audit Metadata
Analyzed At
Sep 17, 2026, 04:28 AM
Package URL
pkg:socket/skills-sh/starchild-ai-agent%2Fofficial-skills%2Faave%2F@3020d143b221888e36102580d2149d3c6c244147a485759806d27a25df7f58e4
Security Audit — socket — aave