rain-trade

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the capability matches the stated purpose, but the skill is high risk because it enables autonomous on-chain trading with real financial consequences and relies on an npm SDK whose official provenance was not verified from first-party protocol documentation. No clear credential theft or covert exfiltration is shown, so this is better classified as vulnerable/high-risk rather than confirmed malware.

Confidence: 85%Severity: 76%
Audit Metadata
Analyzed At
Mar 21, 2026, 01:50 PM
Package URL
pkg:socket/skills-sh/rain1-labs%2Frain-sdk%2Frain-trade%2F@e8dd67713e5b2a2fee411177d5af81fdb86cf3c6