smart-money-tracker
Audited by Socket on Mar 11, 2026
1 alert found:
Obfuscated FileThe smart-money-tracker skill presents a coherent and proportionate footprint for its stated purpose: track onchain smart-money signals and produce human-approval copy plans with strong safety checks. Its reliance on established MCP sources (OnchainOS, GoPlus) and enforced human-in-the-loop for actionable outputs align with a high-trust, finance-focused tool. While the data flows involve external services and wallet/token data, these are expected for the domain and do not indicate credential harvesting or unauthorized exfiltration based on the provided content. The security posture appears conservative (BLOCK for high-risk signals, WARN for softer risks, and mandatory human approval for copy plans), which is appropriate given financial risk concerns. Overall, classify as BENIGN with notable but controlled risk due to external data dependencies and the sensitivity of financial signals.