opentrade-portfolio
Warn
Audited by Socket on Apr 18, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core portfolio-checking purpose mostly matches the commands, but the skill relies on a remote pipe-to-shell installer, forwards API credentials through an external CLI, and oddly requires trading-router discovery for portfolio use. Same-org GitHub release provenance and checksum verification reduce concern, so this is not confirmed malicious, but the install and credential-routing model creates medium security risk.
Confidence: 82%Severity: 58%
Audit Metadata