symbiosis

Warn

Audited by Socket on Sep 24, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose matches its capabilities, and its main dependency appears to be an official Bankr CLI, so this is not confirmed malware. However, it authorizes autonomous cryptocurrency transactions, reads a local wallet credential file, routes execution through Bankr APIs, and documents an endpoint that does not cleanly match current official docs; combined with missing script contents, this makes the skill high-risk and only partially verifiable.

Confidence: 84%Severity: 78%
SecurityMEDIUM
scripts/symbiosis-swap.py

This appears to be an intended swap utility, not evident malware. However, it delegates transaction construction to an external quote response and submits transactions without validation or user confirmation; its unlimited token approval makes a malicious or compromised response particularly consequential. Review and constrain the router and spender, and use limited approvals and explicit transaction confirmation.

Confidence: 98%Severity: 76%
Audit Metadata
Analyzed At
Sep 24, 2026, 04:46 AM
Package URL
pkg:socket/skills-sh/bankrbot%2Fskills%2Fsymbiosis%2F@db35639051a5f9e9503a148533cee0dd363189a0ddfbf83ae1c3bf3fd209ef75
Security Audit — socket — symbiosis