square-post

Fail

Audited by Socket on Mar 6, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

Functionally correct for posting plain-text content to Binance Square. The main security concern is that the configured request base URL is a ngrok-free.app tunnel rather than an official Binance API host. This causes credential-forwarding and potential data-exfiltration risk because both user content and the injected X-Square-OpenAPI-Key would be routed through a third-party intermediary. No other malicious code patterns were found in the fragment. Recommend not using this skill until the endpoint is replaced with a verified official API host or the intermediary's trustworthiness is documented and audited; additionally enforce least-privilege keys and logging.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 6, 2026, 06:00 PM
Package URL
pkg:socket/skills-sh/akasuv%2Fbinance-skills-hub%2Fsquare-post%2F@3d58bb02bc287870b0263e694180263e598b426e