bison-strategy
Warn
Audited by Socket on Mar 18, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s capabilities broadly match its stated purpose as a trading bot, but that purpose itself is high risk: it grants an agent persistent, autonomous authority to trade leveraged crypto positions with limited user visibility. Same-org Senpi references reduce pure supply-chain concern, yet the real-world financial autonomy and intermediary MCP execution path keep overall risk high.
Confidence: 89%Severity: 87%
Audit Metadata