xxyy-trade

Warn

Audited by Socket on Mar 13, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
skills/xxyy-trade/SKILL.md

SUSPICIOUS. The skill is internally coherent for a crypto-trading assistant and shows no classic malware signals such as third-party installers, hidden exfiltration endpoints, or credential theft to unrelated domains. However, it enables real financial transactions using a single bearer API key with wallet-spending authority, performs background wallet/API checks, and relies on XXYY API routes that were not independently verified in public official endpoint documentation. This makes it high-impact and moderately risky even without evidence of malicious intent.

Confidence: 87%Severity: 74%
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is largely aligned with its stated crypto-trading purpose and uses same-brand XXYY endpoints rather than an obvious third-party exfiltration service, so this is not confirmed malware. However, it grants an AI agent high-impact financial capability via a single API key that can both read and trade, includes silent onboarding and wallet auto-selection, and combines untrusted feed/social scanning with execution ability; overall this is a high-risk trading skill that should only run with strong user oversight.

Confidence: 88%Severity: 81%
Audit Metadata
Analyzed At
Mar 13, 2026, 05:16 PM
Package URL
pkg:socket/skills-sh/Jimmy-Holiday%2Fxxyy-trade-skill%2Fxxyy-trade%2F@f93dec0890eb44df05a33c21f9d48f31c019e00f