smart-money-signal-copy-trade

Warn

Audited by Socket on Apr 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill, but not clearly malicious. Its capabilities align with its stated trading purpose and the cited onchainos dependency appears to be official OKX infrastructure; however, it enables autonomous real-world crypto trades, edits local config, and relies on a powerful external CLI for wallet-linked execution. The main concern is financial/action risk and trust in the external execution stack, not covert exfiltration.

Confidence: 87%Severity: 83%
Audit Metadata
Analyzed At
Apr 4, 2026, 09:26 AM
Package URL
pkg:socket/skills-sh/okx%2Fplugin-store-community%2Fsmart-money-signal-copy-trade%2F@10f743221319c51f4c2eb73ce6d0eae442b2d7fb