trade
Warn
Audited by Socket on Mar 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the stated purpose matches token trading, but the skill combines autonomous financial actions with execution of a mutable external CLI (`npx ...@latest`). The main concern is not mismatch of purpose, but high operational risk: a latest-version package can influence quotes, routing, and transaction execution while handling an authenticated wallet session.
Confidence: 83%Severity: 81%
Audit Metadata