copy-trading

Fail

Audited by Socket on Feb 20, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

[Skill Scanner] Instruction to copy/paste content into terminal detected All findings: [CRITICAL] command_injection: Instruction to copy/paste content into terminal detected (CI012) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] This skill's stated purpose (automatic copy trading) is consistent with its requested capabilities (monitor wallets, sign and submit trades). However, the documentation requests high-privilege credentials (private keys and API secrets) but does not state where or how those secrets are stored or whether signing happens locally. Because of that missing provenance and the inherently dangerous ability to sign and submit transactions, this artifact should be treated as suspicious until implementation-level details prove that keys are never exfiltrated and signing is performed locally or by a trusted, auditable mechanism. No direct evidence of malware or obfuscated malicious code is present in the provided documentation, but the potential for credential theft and total-loss of funds is high if the implementation is malicious or insecure. LLM verification: The skill documentation describes a legitimate copy-trading tool and its capabilities are consistent with the stated purpose. However, the examples require highly sensitive credentials (API secrets and raw private key) and no implementation is provided to confirm safe handling or confirm network endpoints. That missing implementation detail creates a supply-chain risk: a malicious or compromised implementation could exfiltrate keys or route operations through third-party proxies. Based on the do

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 20, 2026, 08:51 PM
Package URL
pkg:socket/skills-sh/alsk1992%2Fcloddsbot%2Fcopy-trading%2F@5691a9424289e8726a6359fa4dcf0492e3fe77db