nansen-trade

Fail

Audited by Socket on Mar 9, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's footprint is coherent with its stated purpose: it enables quote-based trading via a legitimate CLI tool requiring API keys and wallet access. The credential requirements and local secret storage are the primary security considerations. The data flows involve legitimate API calls and on-chain actions; there is no evident exfiltration to unknown third parties. The autonomy level remains user-driven through explicit quote and execute steps, though automated pipelines could increase risk if misused. Overall, classify as BENIGN with MEDIUM risk due to credential handling and on-chain signing responsibilities; monitor for secure secret management and proper access controls.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 9, 2026, 04:30 PM
Package URL
pkg:socket/skills-sh/nansen-ai%2Fnansen-cli%2Fnansen-trade%2F@cd65d2e41d57a7b5927177314a45a95215b168e0