ai-trader-tradesync
Warn
Audited by Socket on Mar 25, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The skill is largely purpose-aligned: it sends trading data to AI-Trader's own API and the verified ai4trade.ai domain supports the claimed service relationship. The main risks are supply-chain trust in the remote install/plugin path and the autonomous publication of trading activity once auto-sync is enabled. Overall this is better classified as suspicious/high-risk operational automation than malware.
Confidence: 84%Severity: 74%
Audit Metadata