defillama
Warn
Audited by Socket on Sep 17, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core capability matches a DeFi analytics skill and most network calls go to official DefiLlama endpoints, so it is not fundamentally incompatible with its stated purpose. However, the skill unnecessarily normalizes loading `.env` secrets in shell, places the API key in the request URL path, and introduces an unverified `sc-proxy` intermediary that can intercept API traffic and credentials. That combination makes the data flow moderately risky even though there is no installer malware, no credential harvesting endpoint explicitly named, and no hidden execution.
Confidence: 89%Severity: 56%
Audit Metadata