earn

Warn

Audited by Socket on Mar 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The core purpose and official KuCoin API data flow are mostly coherent, with no third-party routing or installer risk. However, the skill over-normalizes raw secret handling through plaintext files, suggests concealed local secret storage, includes inline account credential placeholders, and overstates auth requirements for at least one public endpoint; these make the footprint broader than necessary for a read-only Earn query skill.

Confidence: 89%Severity: 56%
Audit Metadata
Analyzed At
Mar 14, 2026, 01:04 PM
Package URL
pkg:socket/skills-sh/Kucoin%2Fkucoin-skills-hub%2Fearn%2F@4b575ae8dc4d6a7b530b0949750e1256f56e5291