bankr-signals

Fail

Audited by Socket on Feb 26, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The fragment describes a coherent Bankr Signals integration workflow: provider registration, signed signal publication, and read endpoints with a signing-based authentication model. However, it introduces credential exposure risks via documentation examples and depends on an external signing service, which expands the trust boundary and potential attack surface. To reduce risk, implement secure secret management (env vars, secret vaults), avoid hardcoding or logging API keys, enforce strict transport security, and ensure server-side protections against replay (nonces, timestamp checks) beyond what's shown in the documentation.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 26, 2026, 03:13 AM
Package URL
pkg:socket/skills-sh/BankrBot%2Fskills%2Fbankr-signals%2F@49c865c9fbc45064ea36dd7037cbff477bec39a7