binance-onchain-copy-trader
Audited by Socket on Sep 11, 2026
2 alerts found:
AnomalySecurityBENIGN with elevated operational risk. The skill’s capabilities match its stated purpose as a Binance copy-trading scaffold, install provenance appears same-org and documented, and network flows stay within Binance infrastructure. The main risk is not covert malware behavior but that it enables autonomous live trading with real financial consequences through a trusted external CLI.
This is a legitimate-looking cryptocurrency copy-trading application, not evident malware. It intentionally performs high-impact wallet operations in live mode and persists trading data, creating substantial financial and operational risk. No credential theft, suspicious exfiltration, reverse shell, cryptomining, destructive behavior, or suspicious external domain is evident in the provided code. The external `baw` dependency remains a major trust boundary, and the supplied source contains syntax errors that would prevent execution as written.