pancakeswap

Warn

Audited by Socket on Sep 17, 2026

3 alerts found:

SecurityAnomalyx2
SecurityMEDIUM
pancakeswap-farming/skills/farming-planner/SKILL.md

SUSPICIOUS: the skill is mostly aligned with PancakeSwap farming, and its network endpoints appear same-ecosystem, but its actual footprint exceeds a planner by enabling live on-chain transaction commands and unsolicited telemetry. The main risk is autonomy/financial-action capability plus moderate trust in local scripts and external APIs, not confirmed malware.

Confidence: 86%Severity: 74%
AnomalyLOW
pancakeswap-driver/skills/swap-integration/SKILL.md

BENIGN for purpose alignment and data flow: this is a documentation-style skill for PancakeSwap integration using official npm packages, official API/RPC endpoints, and normal web3 transaction flows. The main risk is not malware but that it equips an agent to execute real on-chain swaps and approvals, including spending via a private key, so overall security risk is medium-high despite low evidence of malicious intent.

Confidence: 91%Severity: 66%
AnomalyLOW
pancakeswap-hub/skills/hub-swap-planner/SKILL.md

SUSPICIOUS. The core behavior mostly matches the stated purpose of planning PancakeSwap Hub swaps, and there is no malware-level installer, obfuscation, or credential theft pattern. However, it forwards a sensitive API token to a backend endpoint that is only partially publicly verifiable, sends telemetry to pancakeswap.ai at initialization, relies on mutable third-party/raw content for some discovery, and can autonomously open wallet handoff links. Those combined signals make it higher risk than a pure documentation skill, but still not fundamentally incompatible with its stated purpose.

Confidence: 87%Severity: 52%
Audit Metadata
Analyzed At
Sep 17, 2026, 04:30 AM
Package URL
pkg:socket/skills-sh/starchild-ai-agent%2Fofficial-skills%2Fpancakeswap%2F@959441f3a56a65f398f0f5bfd07e24ca6b7039de8f21f6b1fda54a10d65c27d8
Security Audit — socket — pancakeswap