web3-trade-simulator

Fail

Audited by Socket on Mar 8, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill largely aligns with its stated purpose of safe, simulated on-chain trading practice with persistent local state and post-trade scoring. However, the install chain (curl | sh from a remote URL) creates a notable supply-chain/remote-execution risk that is not mitigated by the description. The local portfolio handling is appropriate and does not involve real credentials. The data flows (onchainos reads and local writes) are coherent with the educational, non-authentic-trading intent. Overall, the footprint is mostly benign and purpose-appropriate, but the mandatory download-and-execute install pattern elevates risk to SUSPICIOUS and warrants caution and ideally a verified/anchored installation method (e.g., official package registries or signed installers).

Confidence: 98%
Audit Metadata
Analyzed At
Mar 8, 2026, 12:04 PM
Package URL
pkg:socket/skills-sh/wy51ai%2Fweb3-starter-kit%2Fweb3-trade-simulator%2F@c93f462db4320eaed8476e0adaf18a3894bd460e