autoboy

Warn

Audited by Socket on Sep 9, 2026

3 alerts found:

Anomalyx2Security
AnomalyLOW
SKILL.md

BENIGN with elevated operational risk. The skill's capabilities match its stated crypto launch/order-book purpose, and data flows stay on same-org `thefirm.biz` hosts rather than an unrelated proxy. The main risk is proportional but significant: it lets an agent initiate financial actions and route funds into a third-party custodial wallet controlled by The Firm/Privy, so misuse or mistaken execution could cause irreversible loss despite the built-in confirmation guidance.

Confidence: 89%Severity: 62%
AnomalyLOW
catalog.json

No direct malware or malicious payload is evident in this metadata alone. It functions as an integration descriptor for an external skill and a token-trading service. Risk is primarily introduced by installing unreviewed external agent instructions, requesting an API key, and enabling potentially irreversible financial actions. The referenced repository and API behavior must be independently audited before deployment.

Confidence: 97%Severity: 58%
SecurityMEDIUM
references/for-buyers.md

No malware is evident in this documentation-only fragment. The material describes a high-risk third-party custodial trading service: The Firm may spend deposited USDC, automated buys can execute without further transaction-level confirmation after orders are enabled, order details are disclosed to projects, and withdrawals are irreversible. Users should treat the service as custodial and fund only a bounded amount. This assessment cannot verify the external service's implementation, authorization controls, or trustworthiness.

Confidence: 98%Severity: 72%
Audit Metadata
Analyzed At
Sep 9, 2026, 08:49 AM
Package URL
pkg:socket/skills-sh/bankrbot%2Fskills%2Fautoboy%2F@26b83ab2a70ad4d510c27aaad82525689338ca69cf72d1e635f14af647e45243
Security Audit — socket — autoboy