htx-spot-market

Warn

Audited by Socket on May 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Purpose and capabilities are coherent for a public market-data skill, and the documented data flow is read-only with no credential collection. The main issue is trust: the skill depends on an undocumented htx-cli binary whose provenance is not established, so this should be treated as suspicious supply-chain risk rather than malicious behavior.

Confidence: 89%Severity: 78%
Audit Metadata
Analyzed At
May 7, 2026, 04:44 AM
Package URL
pkg:socket/skills-sh/htx-exchange%2Fhtx-skills-hub%2Fhtx-spot-market%2F@becba38ad9c58206eb51647fffeefcfe28205466