strategy-grid-trade

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The trading purpose broadly matches the bot capabilities, but the skill’s footprint is disproportionately risky: it auto-installs and updates executables via curl|sh, routes core functionality through a personal GitHub repo instead of the stated OKX publisher, and authorizes autonomous crypto trading with limited per-action approval. This is high security risk even without proof of malware.

Confidence: 86%Severity: 91%
Audit Metadata
Analyzed At
Mar 18, 2026, 05:32 PM
Package URL
pkg:socket/skills-sh/purong-huang-1121%2Fskills-store%2Fstrategy-grid-trade%2F@7c560e1b258eeeffde5989612d05c859aadc1032