zerion

Warn

Audited by Socket on Sep 24, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
SKILL.md

SUSPICIOUS: mostly coherent and same-org with official Zerion API/data flows, but the skill’s footprint extends beyond read-only wallet intelligence by encouraging autonomous Bankr trading workflows and including a less-well-verified MCP npx path. No confirmed malware or credential theft, but the financial-action adjacency and modest provenance uncertainty make it riskier than a pure documentation/API guide.

Confidence: 88%Severity: 51%
SecurityMEDIUM
references/bankr-integration.md

The document describes portfolio automation rather than evident malware. However, its JavaScript webhook examples have a serious command-injection risk: untrusted token symbols are interpolated into shell commands passed to `exec`. Webhook authenticity is also not shown, so exposed handlers could permit unauthorized trading actions. Do not deploy these examples as written; validate and constrain inputs, verify webhook signatures, and avoid shell-string execution.

Confidence: 98%Severity: 78%
Audit Metadata
Analyzed At
Sep 24, 2026, 04:46 AM
Package URL
pkg:socket/skills-sh/bankrbot%2Fskills%2Fzerion%2F@83eaeee4e81f2474f89e9dfb0064a131086fa037b2f0ae561303faec5c2450a9
Security Audit — socket — zerion