opentrade-gateway

Warn

Audited by Socket on Mar 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is mostly coherent with its stated blockchain gateway purpose, and the installer appears same-org and checksum-verified. However, it still uses a remote curl|sh installer, forwards API credentials to an external CLI/service, and enables autonomous on-chain broadcasting of signed transactions, making it medium risk rather than benign.

Confidence: 88%Severity: 58%
Audit Metadata
Analyzed At
Mar 22, 2026, 12:52 PM
Package URL
pkg:socket/skills-sh/6551Team%2Fopenskills%2Fopentrade-gateway%2F@42b25680f5db0ed2ba659801de9aec2e2d7aba60