kestrel-strategy

Warn

Audited by Socket on Apr 26, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the trading purpose matches the skill description, but the operational footprint is high risk. It enables autonomous leveraged trading and relies on Senpi-controlled intermediary infrastructure and runtime components that receive credentials instead of using a clearly documented direct Hyperliquid API path.

Confidence: 86%Severity: 84%
Audit Metadata
Analyzed At
Apr 26, 2026, 05:45 AM
Package URL
pkg:socket/skills-sh/Senpi-ai%2Fsenpi-skills%2Fkestrel-strategy%2F@4b7cad25062262bebde0792c64f54b540f40f9f0