rain-trade
Warn
Audited by Socket on Mar 21, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the capability matches the stated purpose, but the skill is high risk because it enables autonomous on-chain trading with real financial consequences and relies on an npm SDK whose official provenance was not verified from first-party protocol documentation. No clear credential theft or covert exfiltration is shown, so this is better classified as vulnerable/high-risk rather than confirmed malware.
Confidence: 85%Severity: 76%
Audit Metadata