fiat

Warn

Audited by Socket on Apr 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill is mostly aligned with its stated Binance fiat purpose and routes data only to the official Binance API, so it is not malware. Risk comes from its credential-handling design: automatic secret retrieval from multiple local files, optional use without per-action confirmation, and storing new credentials in TOOLS.md are broader and less controlled than necessary. Overall this is suspicious-but-purpose-consistent, with medium security risk driven by secret access patterns rather than exfiltration behavior.

Confidence: 89%Severity: 56%
Audit Metadata
Analyzed At
Apr 1, 2026, 02:35 PM
Package URL
pkg:socket/skills-sh/binance%2Fbinance-skills-hub%2Ffiat%2F@46f57dd58a2901c262050d5804a6de56e08d8058