binance-onchain-copy-trader

Warn

Audited by Socket on Sep 11, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
SKILL.md

BENIGN with elevated operational risk. The skill’s capabilities match its stated purpose as a Binance copy-trading scaffold, install provenance appears same-org and documented, and network flows stay within Binance infrastructure. The main risk is not covert malware behavior but that it enables autonomous live trading with real financial consequences through a trusted external CLI.

Confidence: 92%Severity: 68%
SecurityMEDIUM
scripts/copytrader.py

This is a legitimate-looking cryptocurrency copy-trading application, not evident malware. It intentionally performs high-impact wallet operations in live mode and persists trading data, creating substantial financial and operational risk. No credential theft, suspicious exfiltration, reverse shell, cryptomining, destructive behavior, or suspicious external domain is evident in the provided code. The external `baw` dependency remains a major trust boundary, and the supplied source contains syntax errors that would prevent execution as written.

Confidence: 96%Severity: 78%
Audit Metadata
Analyzed At
Sep 11, 2026, 12:45 PM
Package URL
pkg:socket/skills-sh/binance%2Fbinance-skills-hub%2Fbinance-onchain-copy-trader%2F@bcaf3c677a862563796bc170c173b738b6aaf8b24d16bac33de1fb59f539e8fd
Security Audit — socket — binance-onchain-copy-trader