signals

Fail

Audited by Socket on Feb 20, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The described package/skill legitimately implements automated trading triggered by external signals, but its design contains significant operational and supply-chain risks. The most critical red flags are requiring a full Solana private key and example usage of a third-party-hosted webhook endpoint (clodds.io) without documented trust guarantees. These create realistic avenues for credential exposure and unauthorized draining of funds if keys are stored/transmitted insecurely or if webhook traffic is intercepted/abused. There is no explicit evidence of malware in the provided fragment, but the feature set is dangerous without concrete safeguards: local-only signing, hardware wallet support, limited-scope keys, mandatory webhook authentication, whitelists/approval flows, trade caps, and transparent logging. Recommend: do not provide your main private key, require code review of key handling and network endpoints, prefer local signing or hardware-key integration, verify ownership/trust of any hosted webhook provider, and add mandatory safety controls before enabling automatic live trading.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 20, 2026, 08:53 PM
Package URL
pkg:socket/skills-sh/alsk1992%2Fcloddsbot%2Fsignals%2F@61eab4e60d680a1d794aae788991bf844fe926c0