bankr-signals

Warn

Audited by Socket on Apr 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core API usage is mostly aligned with a trading-signals skill and uses consistent official endpoints, so this is not confirmed malware. However, the skill enables financially consequential autonomous behavior, recommends third-party managed signing with API keys, and most importantly instructs the agent to periodically fetch and follow external heartbeat markdown, creating a high prompt-injection and action-abuse risk.

Confidence: 88%Severity: 74%
Audit Metadata
Analyzed At
Apr 1, 2026, 02:45 AM
Package URL
pkg:socket/skills-sh/bankrbot%2Fmoltbot-skills%2Fbankr-signals%2F@6a8daec56b3a8a08b234df68171c6b8f0d7ae1a9