polyhub_copy
Warn
Audited by Socket on Apr 1, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s capabilities mostly match its stated trading purpose, but it enables high-impact financial actions and sends the user’s API key to a fixed test/dev-looking API host whose official provenance is not well verified by the supplied evidence. This is not confirmed malware, but it is a high-risk skill due to autonomous trading potential and weak endpoint trust.
Confidence: 89%Severity: 78%
Audit Metadata