senpi-onboard

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

BENIGN in purpose alignment and data routing, but HIGH RISK in operation: this skill provisions real trading credentials, may generate a custodial wallet locally, and prepares an AI agent for autonomous financial actions. No clear credential-harvesting or off-platform exfiltration is present, so this is not confirmed malware; it is a sensitive onboarding skill that should be treated as high security risk due to financial autonomy and secret handling.

Confidence: 87%Severity: 78%
Audit Metadata
Analyzed At
Mar 13, 2026, 08:26 PM
Package URL
pkg:socket/skills-sh/Senpi-ai%2Fsenpi-skills%2Fsenpi-onboard%2F@2d7e76b90d70915b69763a2203c1662e57624cea