bankr

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The Bankr skill describes a legitimate high-privilege autonomous trading assistant with broad cross-chain capabilities. However, plaintext storage of API keys, OTP onboarding, and the ability to perform arbitrary transactions and raw calldata introduce substantial security and supply-chain risks. Mitigations should include encrypted secret storage with access controls, per-action scopes and approvals, explicit user confirmations for high-risk operations, robust auditing/logging, and hardened onboarding to prevent credential leakage or playback attacks.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 05:14 AM
Package URL
pkg:socket/skills-sh/ThinkfleetAI%2Fthinkfleet-engine%2Fbankr%2F@c54bc7f9d21050c556d935f9572d6ff12248c76d