htx-spot-market
Warn
Audited by Socket on May 7, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
Purpose and capabilities are coherent for a public market-data skill, and the documented data flow is read-only with no credential collection. The main issue is trust: the skill depends on an undocumented htx-cli binary whose provenance is not established, so this should be treated as suspicious supply-chain risk rather than malicious behavior.
Confidence: 89%Severity: 78%
Audit Metadata