derivatives-trading-options

Warn

Audited by Socket on Mar 19, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill’s API scope matches its Binance trading purpose and it uses official Binance endpoints, so there is no strong sign of credential harvesting or malware. However, it enables autonomous financial actions and instructs the agent to read/store raw API credentials in plaintext files, which is a significant security risk for an AI skill even with masking guidance and a mainnet confirmation step.

Confidence: 91%Severity: 74%
Audit Metadata
Analyzed At
Mar 19, 2026, 10:02 AM
Package URL
pkg:socket/skills-sh/binance%2Fbinance-skills-hub%2Fderivatives-trading-options%2F@6fad024f8efa2533e89d7417cb900767941682be