trade

Warn

Audited by Socket on Mar 26, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill is purpose-aligned with trade research and posting to paste.trade, and its main external API flow appears consistent with that service. The main risk is not hidden malware but high-impact autonomy: it can ingest untrusted content, execute local scripts, store API keys, update its own repo, and publicly post trade outputs without per-action confirmation. That makes it suspicious/high-risk rather than benign.

Confidence: 86%Severity: 82%
Audit Metadata
Analyzed At
Mar 26, 2026, 01:26 AM
Package URL
pkg:socket/skills-sh/rohunvora%2Fpaste-trade%2Ftrade%2F@b9fa708ba8c3a6d441b4df089d072efe26a7ef1c