fiat

Warn

Audited by Socket on Sep 14, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

The skill provides fiat-capability functionality and routes data to Binance-owned domains, while performing credential discovery and automatic retrieval of secrets from local files, with credentials potentially stored in a local document (TOOLS.md). This design exposes credentials and expands credential-management access beyond the intended functionality, though there is no strong evidence of malware or third-party credential theft.

Confidence: 87%Severity: 58%
AnomalyLOW
references/sapi-endpoints.md

The fragment describes a legitimate Binance fiat API integration with sensitive credential handling and financially consequential deposit/withdrawal capabilities. It contains no clear malicious behavior, suspicious exfiltration destination, obfuscated code, or backdoor. It should be treated as high-impact integration guidance because compromised or misused credentials could enable Binance account access or withdrawals; credentials should remain outside version control and transactions should require explicit confirmation.

Confidence: 96%Severity: 68%
Audit Metadata
Analyzed At
Sep 14, 2026, 08:08 PM
Package URL
pkg:socket/skills-sh/binance%2Fbinance-skills-hub%2Ffiat%2F@240bf9995e7f410afb35d03c52382b62500c5fbb58b5d50c4ddd2d83013bc546
Security Audit — socket — fiat