bison-strategy

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s capabilities broadly match its stated purpose as a trading bot, but that purpose itself is high risk: it grants an agent persistent, autonomous authority to trade leveraged crypto positions with limited user visibility. Same-org Senpi references reduce pure supply-chain concern, yet the real-world financial autonomy and intermediary MCP execution path keep overall risk high.

Confidence: 89%Severity: 87%
Audit Metadata
Analyzed At
Mar 18, 2026, 10:09 PM
Package URL
pkg:socket/skills-sh/senpi-ai%2Fsenpi-skills%2Fbison-strategy%2F@7487a938c885867a06604fd93479224ae44cfe9a