blofin-portfolio-analyst

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The BloFin Portfolio Analyst appears to be a focused, credentialed data-aggregation tool for BloFin trading data. Its footprint—reading balance, positions, fills, orders, and tickers from a user’s authenticated BloFin account to compute PnL, margins, and performance reports—aligns with its described purpose. Riskiest aspects are standard credential handling (environment variables) and ensuring outputs do not leak sensitive account data. No evidence of supply-chain risks, autonomous real-world actions, or exfiltration channels is present in the provided description. Overall, the security posture is reasonable for a legitimate developer tool intended to analyze a user’s own trading data, but requires careful handling of credentials in logs and UI to remain benign.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 04:11 PM
Package URL
pkg:socket/skills-sh/blofin%2Fblofin-skills-hub%2Fblofin-portfolio-analyst%2F@10da686f0f78b2d56ef045613503d9d846ecdc68