mexc-futures

Warn

Audited by Socket on Sep 18, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core capability matches the stated purpose of MEXC futures trading, and the requested exchange credentials are broadly proportionate. However, it enables high-impact autonomous financial actions, contains a misleading 'No KYC' claim contradicted by official docs, and omits implementation details needed to verify whether credentials and trade data go only to official MEXC endpoints and a legitimate local database.

Confidence: 89%Severity: 78%
AnomalyLOW
index.ts

The fragment is a legitimate MEXC futures trading command handler, not apparent malware. It intentionally uses API credentials to query and modify a trading account and records activity in a database. The main risks are high-impact financial actions, potentially missing authorization controls in this module, and permissive numeric parsing. Review the imported exchange and database implementations and the command authorization layer before deployment.

Confidence: 96%Severity: 58%
Audit Metadata
Analyzed At
Sep 18, 2026, 03:47 AM
Package URL
pkg:socket/skills-sh/alsk1992%2Fcloddsbot%2Fmexc-futures%2F@9f011362d77da785c42c00b0542fac2e83b0d2d9dd28c98bf1e9e339dd05b944
Security Audit — socket — mexc-futures