defillama

Warn

Audited by Socket on May 11, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's main purpose and official DefiLlama API usage are broadly coherent and there is no installer or malware-like payload, but the undocumented 'sc-proxy' guidance routes API-key-bearing traffic through an intermediary and is not verified as an official DefiLlama component. Combined with stale/inconsistent endpoint documentation, this creates medium security risk centered on credential/data-flow integrity rather than confirmed malicious behavior.

Confidence: 84%Severity: 62%
Audit Metadata
Analyzed At
May 11, 2026, 03:51 PM
Package URL
pkg:socket/skills-sh/starchild-ai-agent%2Fofficial-skills%2Fdefillama%2F@7048e9dc4512e73ea56a9eebbfcbbc6997790339