opentrade-token

Warn

Audited by Socket on Mar 11, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill footprint is coherent with token discovery and analytics, but it uses a high-risk download-execute installer from a non-verifiable source and relies on user-supplied credentials via a .env. This combination is suspicious and warrants caution: the installer could be tampered or poisoned, and credentials could be exposed if logs/logs redaction are not enforced. Overall assessment: SUSPICIOUS due to download/execute pattern and unverifiable dependencies, with elevated risk from credential handling and potential third-party CLI onboarding. If the installer were replaced with an officially signed package or a pinned, signed binary from a trusted registry, and credential handling was hardened (e.g., tokens fetched via a secure in-tool vault with scoped permissions), the risk would drop toward Benign.

Confidence: 98%Severity: 72%
Audit Metadata
Analyzed At
Mar 11, 2026, 08:34 AM
Package URL
pkg:socket/skills-sh/6551Team%2Fopenskills%2Fopentrade-token%2F@3ce247140e04addc551be8782f204ae6fcdd40f0