ctp-api

Fail

Audited by Socket on Mar 4, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
references/callbacks_part1_ab.md

The code fragment does not exhibit classic malware behavior (no network exfiltration, reverse shell, or obfuscation). It does, however, present a meaningful operational security risk: hardcoded account/order identifiers and unbounded retry loops around authoritative trading API calls can cause accidental or repeated live trades and credential leakage. Treat the code as non-malicious but high-risk for production use. Before deploying: remove hardcoded credentials, externalize and protect secrets, add idempotency and max-retry/backoff logic, require explicit confirmation for live orders, and improve error handling and logging.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 4, 2026, 03:28 PM
Package URL
pkg:socket/skills-sh/algoderiv%2Fagent-skills%2Fctp-api%2F@c306f7c8ffc6168850509f4e4ff2aa4d3282d088