robonet-workbench
Audited by Socket on Feb 16, 2026
1 alert found:
SecurityThis document is a skill specification describing a high-privilege trading/workbench integration (Robonet MCP). There is no direct evidence of malware or obfuscated code in the text. The primary risks are operational and supply-chain/trust related: the skill requires API keys and wallet credentials and routes many sensitive operations through a third-party MCP server (possible credential exposure or centralized data access). Before use, confirm whether wallet private keys ever leave the user's environment, examine Robonet's security/retention policy, and restrict agent/tool permissions (require human confirmation before deployments or spending). Treat the skill as SUSPICIOUS from a supply-chain/trust perspective (requires strong vetting) but not overtly malicious.