bankr

Fail

Audited by Socket on Feb 20, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

[Skill Scanner] Natural language instruction to download and install from URL detected Benign overall with normal risk considerations for a financial trading integration. The skill footprint—prompt handling, API-key-based auth, and API-driven actions—is coherent with its stated purpose. Critical improvements should include explicit per-command permissions, user-confirmation prompts for high-stakes actions (e.g., token deployment, raw transactions), secure handling and rotation of API keys, audit logging, input validation, and rate limiting to mitigate operational and financial risk. LLM verification: The SKILL.md itself contains no code-level evidence of malware or obfuscation; it is a high-level manifest describing powerful financial operations mediated by the external Bankr service. The principal security risk stems from centralizing powerful credentials (BANKR_API_KEY) with an external service and enabling raw transaction forwarding and automated fund-moving features without documented least-privilege controls or confirmation safeguards. Recommend: do not provide a full-custody API key wi

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 20, 2026, 08:52 PM
Package URL
pkg:socket/skills-sh/alsk1992%2Fcloddsbot%2Fbankr%2F@2bd513174c00f60818342b04265fa40dcfbf5e79