mm

Warn

Audited by Socket on Feb 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

[Skill Scanner] Credential file access detected This skill's declared purpose, required credentials, and described capabilities are consistent and proportionate for a market-making bot. Nothing in the provided YAML/markdown indicates malicious behavior, obfuscation, or hidden credential exfiltration. The primary security concern is operational: the skill requires exchange API keys which, if misused or leaked, could enable unauthorized trading or financial loss. Reviewers should inspect the actual implementation files (network calls, logging, storage) to confirm no unexpected data flows or third-party proxies are present before deployment. LLM verification: The provided SKILL.md documents a plausible market-making automation skill with appropriate controls on paper. There is no evidence in the supplied text of malware, backdoors, or obfuscated malicious behavior. However, the file lacks critical implementation details about credential handling, endpoint destinations, and logging practices. Because the bot performs high-impact networked actions (order placement/cancellation), the implementation must be audited for: direct connection to official exch

Confidence: 85%Severity: 75%
Audit Metadata
Analyzed At
Feb 20, 2026, 08:52 PM
Package URL
pkg:socket/skills-sh/alsk1992%2Fcloddsbot%2Fmm%2F@e84737031bfcce53e73889b01094a56fe26ae0a5