opentrade-market

Warn

Audited by Socket on Mar 22, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s market-data purpose largely matches its commands, but it requires executing a remotely installed CLI and forwarding API credentials to that binary. Same-org GitHub hosting and checksums reduce the chance of outright malware, yet the mutable curl|sh installer plus unverifiable binary/credential path make the overall risk high.

Confidence: 86%Severity: 83%
Audit Metadata
Analyzed At
Mar 22, 2026, 12:52 PM
Package URL
pkg:socket/skills-sh/6551Team%2Fopenskills%2Fopentrade-market%2F@a49f06419a1f8d8d7c17b578ff3cd8a6cec292a1