smart-dca-bot

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s core trading capabilities align with its stated Coinbase DCA purpose, and the install path shown is a normal pip/local-Python workflow rather than a malicious download-execute chain. The main risk comes from autonomous financial actions, powerful exchange credentials, and an additional Seren scheduling control plane whose exact public verification is limited. This looks more like a high-risk trading automation skill than confirmed malware.

Confidence: 87%Severity: 78%
Audit Metadata
Analyzed At
Mar 21, 2026, 02:46 AM
Package URL
pkg:socket/skills-sh/serenorg%2Fseren-skills%2Fsmart-dca-bot%2F@31ec7ce02b7c7907877b771166b5d3f7a65e0150