top-rank-tokens-sniper

Warn

Audited by Socket on Apr 4, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
assets/dashboard.html

No direct malware/backdoor behavior is evident in this client-side fragment. However, it repeatedly inserts backend-provided strings into the DOM using innerHTML (positions, trades, roster, logs) without escaping or sanitization. This creates a high-impact DOM XSS risk if an attacker can influence the backend state/logs or the content stored and served to this UI. If not mitigated with strict backend-side sanitization and/or a CSP, this dashboard could be compromised via script injection and then potentially manipulate the app’s start/stop/mode/reset actions through user/browser context.

Confidence: 66%Severity: 77%
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is purpose-aligned, but it grants an AI agent autonomous cryptocurrency trading capability with real financial consequences. Install provenance for onchainos looks relatively coherent and same-org, lowering malware concern, yet the live-trading and wallet-delegation footprint makes the skill high security risk overall.

Confidence: 88%Severity: 79%
Audit Metadata
Analyzed At
Apr 4, 2026, 09:26 AM
Package URL
pkg:socket/skills-sh/okx%2Fplugin-store-community%2Ftop-rank-tokens-sniper%2F@3a77b723d971e84f1aec53bd98589d0a94bdc27c