bankr
Warn
Audited by Socket on Mar 1, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The Bankr skill describes a legitimate high-privilege autonomous trading assistant with broad cross-chain capabilities. However, plaintext storage of API keys, OTP onboarding, and the ability to perform arbitrary transactions and raw calldata introduce substantial security and supply-chain risks. Mitigations should include encrypted secret storage with access controls, per-action scopes and approvals, explicit user confirmations for high-risk operations, robust auditing/logging, and hardened onboarding to prevent credential leakage or playback attacks.
Confidence: 75%Severity: 75%
Audit Metadata