zerion
Audited by Socket on Sep 24, 2026
2 alerts found:
AnomalySecuritySUSPICIOUS: mostly coherent and same-org with official Zerion API/data flows, but the skill’s footprint extends beyond read-only wallet intelligence by encouraging autonomous Bankr trading workflows and including a less-well-verified MCP npx path. No confirmed malware or credential theft, but the financial-action adjacency and modest provenance uncertainty make it riskier than a pure documentation/API guide.
The document describes portfolio automation rather than evident malware. However, its JavaScript webhook examples have a serious command-injection risk: untrusted token symbols are interpolated into shell commands passed to `exec`. Webhook authenticity is also not shown, so exposed handlers could permit unauthorized trading actions. Do not deploy these examples as written; validate and constrain inputs, verify webhook signatures, and avoid shell-string execution.