senpi-trading-runtime

Warn

Audited by Socket on Apr 2, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally coherent for Senpi runtime management, but its core function is autonomous financial action on live positions, which is inherently high risk for an AI agent. Credentials and wallet data are proportionate to purpose, and there is no clear exfiltration pattern, but missing installer provenance and local token storage add moderate operational risk.

Confidence: 86%Severity: 81%
Audit Metadata
Analyzed At
Apr 2, 2026, 08:43 AM
Package URL
pkg:socket/skills-sh/Senpi-ai%2Fsenpi-skills%2Fsenpi-trading-runtime%2F@baacf6c693225819cbee1c4778f3b9bc6eeb0a2a