scorpion-tracker

Warn

Audited by Socket on Apr 26, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s capabilities match its stated purpose as an automated trading agent, and the install source is same-org and likely legitimate, but it still enables high-risk autonomous financial actions, uses unpinned raw-file installs, and forwards credentials into scheduled command execution. This looks more like a high-risk trading skill than credential-stealing malware.

Confidence: 87%Severity: 81%
Audit Metadata
Analyzed At
Apr 26, 2026, 05:45 AM
Package URL
pkg:socket/skills-sh/Senpi-ai%2Fsenpi-skills%2Fscorpion-tracker%2F@f611ebdd8567549e4ab3833c30d7a0ec9a03a648