aster-api-spot-account-v3

Fail

Audited by Socket on Mar 9, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill centers on legitimate access to a trading/testnet API, including sensitive actions like withdrawals and API key creation. While functionality is coherent with its stated purpose, the footprint raises meaningful security considerations around credential handling, per-action user consent, and auditability. Without explicit safeguards (credential storage policy, per-action confirmations, and secure signing/rotation), the risk profile is elevated to suspicious. Recommend implementing explicit user prompts for high-risk actions (withdraw, createApiKey), strong credential management (never store secrets in plain memory, use secure storage, rotate keys), and clear data-flow/documentation on TLS behavior and auditing.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 9, 2026, 01:34 PM
Package URL
pkg:socket/skills-sh/asterdex%2Faster-skills-hub%2Faster-api-spot-account-v3%2F@c5913e38facf4575c9bfdbe1da3b4b4bdbf4f114