jackal-tracker
Warn
Audited by Socket on Apr 26, 2026
2 alerts found:
Securityx2Securitylegacy-fox-pyramid-concept/SKILL.md
MEDIUMSecurityMEDIUM
legacy-fox-pyramid-concept/SKILL.md
SUSPICIOUS due to autonomous trading and transitive dependence on the FOX skill, not because of clear malware behavior. The skill’s purpose and capabilities are broadly aligned, but it enables high-impact financial actions with limited transparency and incomplete implementation detail in the fragment provided.
Confidence: 84%Severity: 76%
SecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The skill is purpose-consistent but high risk because its core function is autonomous crypto trading with wallet-backed execution and LLM-mediated decisions. Install provenance appears same-org and not overtly malicious, yet the financial autonomy, credential use, and scheduled execution make this a dangerous skill even without clear evidence of credential theft or hidden exfiltration.
Confidence: 88%Severity: 86%
Audit Metadata