kodiak-strategy

Warn

Audited by Socket on Mar 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s purpose and capabilities are internally consistent for an autonomous trading bot, but it is high risk because it enables recurring leveraged financial trades with limited user visibility and no explicit per-trade approval. Install trust is only partially verifiable: same-org Senpi references look legitimate, yet the required Senpi MCP runtime is not specified enough here to fully assess provenance.

Confidence: 87%Severity: 86%
Audit Metadata
Analyzed At
Mar 16, 2026, 04:17 AM
Package URL
pkg:socket/skills-sh/Senpi-ai%2Fsenpi-skills%2Fkodiak-strategy%2F@42d01e3e90a943cc7e0fe2a6373e37920699803f