fiat

Warn

Audited by Socket on Mar 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The core capability matches the stated Binance fiat purpose and network flow stays on Binance's official API, so there is no strong malware or exfiltration signal. Risk comes from handling plaintext API secrets, persisting them in TOOLS.md, and enabling real-world fiat transactions; these are sensitive but still broadly coherent with the skill's stated function.

Confidence: 89%Severity: 54%
Audit Metadata
Analyzed At
Mar 20, 2026, 09:50 AM
Package URL
pkg:socket/skills-sh/binance%2Fbinance-skills-hub%2Ffiat%2F@0eade3158ce16300d5ffe9b90d5d068b0aece7a3