trading

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's capabilities fit its stated trading purpose and the npm install source appears legitimate, but it enables autonomous high-impact financial actions and requires a raw wallet private key plus API credentials routed through a centralized managed-custody API. This is not confirmed malware, but it is a high-risk skill that should only be used with strict user approval and strong key-isolation controls.

Confidence: 90%Severity: 86%
Audit Metadata
Analyzed At
Mar 21, 2026, 02:46 AM
Package URL
pkg:socket/skills-sh/serenorg%2Fseren-skills%2Ftrading%2F@05fde329b7187933cda1c9eff1eb2d1d590e7c93