lp-agent

Fail

Audited by Socket on Feb 28, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The lp-agent skill is coherent with its stated purpose of orchestrating automated LP workflows using Hummingbot API and Gateway. However, credential handling weaknesses (default admin/admin, private key prompts/log exposure) create meaningful security risks. The assessment remains suspicious-to-high-risk due to secret management gaps and potential exposure via logs/history, though there is no evidence of malicious payloads or active data exfiltration. Recommended improvements include eliminating default credentials, implementing secure key-entry (non-echoed, ephemeral in-memory handling), and introducing a secrets management layer for API keys and wallet material.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 28, 2026, 09:29 AM
Package URL
pkg:socket/skills-sh/hummingbot%2Fskills%2Flp-agent%2F@e09d899aa164a490f1f312102d197e337ff8417a