shark

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s behavior is mostly aligned with its stated purpose, but that purpose is high-risk autonomous leveraged trading. The biggest concerns are autonomous real-world financial actions and credential forwarding into a third-party CLI (`mcporter`) whose provenance is not same-org or pinned in the skill. No clear evidence of credential theft or unrelated exfiltration is shown, so this is not confirmed malware, but it is a high-risk trading automation skill.

Confidence: 90%Severity: 90%
Audit Metadata
Analyzed At
Mar 13, 2026, 06:12 PM
Package URL
pkg:socket/skills-sh/Senpi-ai%2Fsenpi-skills%2Fshark%2F@431d8b5c21205590423689d5edbb1b191ac96f1b