xaut-trade

Warn

Audited by Socket on Mar 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill presents a coherent narrative for automated XAUT trading via Foundry cast with market and limit orders, but includes high-risk supply-chain patterns (curl | bash for installer), heavy credential access (keystore, private keys), and external data flows that could be leveraged for credential exposure or data leakage if not properly controlled. The combination of unverifiable binary installation and credential-forwarding potential, plus transitive dependency risk, places the overall assessment in Suspicious range with notable security concerns; not clearly malicious by intent, but requires stringent provenance, least-privilege execution, and explicit user consent/approval for all credential usage and external data access.

Confidence: 60%Severity: 75%
Audit Metadata
Analyzed At
Mar 9, 2026, 03:46 AM
Package URL
pkg:socket/skills-sh/aurehub%2Fskills%2Fxaut-trade%2F@9d3223caebf33066ea8b6aef7f96d9e1708f0d6e