croc-strategy

Warn

Audited by Socket on Mar 12, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill is aimed at autonomous financial trading (funding-rate arbitrage) with automated entry/exit using a DSL High Water Mode. This entails real-world asset trading decisions executed by an AI agent without per-action user confirmation, which introduces high risk of financial loss or unintended trades. There are no explicit unsecured data exfiltration patterns, but credential handling is not defined and is a critical gap for secure deployment. Overall, the footprint is coherent with the stated purpose (autonomous trading) but raises significant security and risk concerns due to the autonomous execution model, undefined credential management, and potential for prolonged exposure due to disabled time-based exits.

Confidence: 98%Severity: 85%
Audit Metadata
Analyzed At
Mar 12, 2026, 06:28 PM
Package URL
pkg:socket/skills-sh/Senpi-ai%2Fsenpi-skills%2Fcroc-strategy%2F@31ebbb9f16ba5ccf72ff7e5626ba63a189540266