trade-prediction-markets

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

This document itself is not directly malicious: no obfuscated code, hardcoded credentials, or suspicious network activity are present. The primary security concerns are operational rather than intrinsic to the text: (1) create_prediction_market_strategy produces executable Python code that could perform arbitrary, potentially harmful actions when executed; (2) the promised live deployment lacks described secure credential handling and execution sandboxing. Recommendation: treat generated strategies as untrusted — require mandatory human code review, run generated code in isolated sandboxes with restricted outbound network access and no access to secret keys, and design a secure credential handling architecture (KMS/hardware wallet/signing service with least privilege) before enabling live trading. With these mitigations the platform risk can be reduced. Current overall assessment: moderate security risk but low immediate maliciousness.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 15, 2026, 08:38 PM
Package URL
pkg:socket/skills-sh/robonet-tech%2Fskills%2Ftrade-prediction-markets%2F@b1feda87e223e3552e295f80a3185ca61fa8f204