ai-trader-tradesync

Warn

Audited by Socket on Mar 25, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill is largely purpose-aligned: it sends trading data to AI-Trader's own API and the verified ai4trade.ai domain supports the claimed service relationship. The main risks are supply-chain trust in the remote install/plugin path and the autonomous publication of trading activity once auto-sync is enabled. Overall this is better classified as suspicious/high-risk operational automation than malware.

Confidence: 84%Severity: 74%
Audit Metadata
Analyzed At
Mar 25, 2026, 04:47 AM
Package URL
pkg:socket/skills-sh/HKUDS%2FAI-Trader%2Fai-trader-tradesync%2F@a65d79275b5e7ea9e0012583d6bbbd8b4770387c