aicoin

Warn

Audited by Socket on Mar 5, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The improved assessment confirms that the OpenClaw AiCoin skill is coherent with crypto data access and trading automation but carries notable supply-chain and credential-management risks due to external repo deployment (Freqtrade), multi-source credentials, and proxy-enabled network paths. It remains potentially benign if provenance is verified, dependencies pinned, and credential handling strictly enforced with sanitized logs. Treat as MARGINALLY RISKY; require provenance verification for external repos, implement secret management (vaults), and enforce strict logging controls. If provenance cannot be confirmed, downgrade to SUSPECT and perform thorough vetting before production use.

Confidence: 63%Severity: 58%
Audit Metadata
Analyzed At
Mar 5, 2026, 06:26 AM
Package URL
pkg:socket/skills-sh/aicoincom%2Faicoin-skills%2Faicoin%2F@80595833ee5225ceb134fafdc0fa11067e42d9b3