bankr-signals

Fail

Audited by Socket on Mar 9, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The Bankr Signals skill presents a coherent capability set: provider registration, signed signal publication, and public signal reading with blockchain-backed verification. Data flows properly leverage signed requests to a remote API, with read endpoints being public. The footprint is proportionate to the stated purpose, but there are notable security considerations around credential handling, signing workflows, and public exposure of provider data. No unverifiable binaries are evident, and no autonomous real-world actions beyond API interactions are described. Overall, the skill is SUSPICIOUS to MEDIUM risk due to credential exposure potential and data-flow exposure, but not malicious given the documented API-centric design.

Confidence: 98%Severity: 55%
Audit Metadata
Analyzed At
Mar 9, 2026, 11:46 PM
Package URL
pkg:socket/skills-sh/bankrbot%2Fclawdbot-skill%2Fbankr-signals%2F@49c865c9fbc45064ea36dd7037cbff477bec39a7