vip-loan
Warn
Audited by Socket on Mar 20, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The skill is purpose-aligned and sends data to Binance's official API, so it is not overtly malicious. However, it enables real-world financial actions and instructs the agent to ingest and persist raw Binance API secrets in TOOLS.md, creating substantial credential-handling and account-abuse risk.
Confidence: 89%Severity: 78%
Audit Metadata