opentrade-dex-swap

Warn

Audited by Socket on Mar 22, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The trading purpose matches the swap/quote capabilities, but the trust model is weak: the skill repeatedly installs an unverifiable external CLI via raw GitHub pipe-to-shell and then feeds it API credentials and trading data. Because it facilitates real financial actions and credential forwarding through a black-box tool, overall security risk is high even without proof of outright malware.

Confidence: 86%Severity: 84%
Audit Metadata
Analyzed At
Mar 22, 2026, 12:53 PM
Package URL
pkg:socket/skills-sh/6551Team%2Fopenskills%2Fopentrade-dex-swap%2F@86bedc78fc8c56f904ff8b645734770d56acdd65