blofin-account-manager

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The BloFin Account Manager skill is largely coherent with its stated purpose: it provides authenticated access to balance and position data and allows controlled changes to leverage, margin mode, and position mode with user confirmations. The credential-handling pattern (environment-stored API keys) is typical but introduces potential leakage risks if logs or prompts expose secrets. Network flows align with official API usage; ensure endpoints are trusted and TLS is enforced. Overall risk is moderate (securityRisk ~0.55) due to credential exposure potential and the need for stronger logging/audit controls and secret-handling guidance. Consider adding explicit secret handling policies, robust auditing for sensitive changes, rate-limiting/retry logic, and explicit TLS/transport security specifications.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 04:52 PM
Package URL
pkg:socket/skills-sh/blofin%2Fblofin-skills-hub%2Fblofin-account-manager%2F@d8a757c8aeb768ef6d83fd289ae7e290a0381582