pangolin-strategy

Warn

Audited by Socket on Apr 26, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's behavior is largely consistent with its stated purpose as a Hyperliquid funding-rate strategy, but it enables autonomous leveraged trading with real financial consequences and appears to rely on Senpi-hosted runtime infrastructure. The main concern is high operational risk and credential/data exposure through the runtime path, not confirmed malware.

Confidence: 85%Severity: 79%
Audit Metadata
Analyzed At
Apr 26, 2026, 05:45 AM
Package URL
pkg:socket/skills-sh/Senpi-ai%2Fsenpi-skills%2Fpangolin-strategy%2F@8b8a1a60bdab6add5d03c41c442162703cb35a17