blave-quant

Warn

Audited by Socket on May 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities largely match its stated quant/trading purpose and use mostly official endpoints, so it is not overtly malicious. But it is high-impact and unusually broad: it aggregates many exchange credentials, enables real-money trading and transfers, includes a CAPTCHA-scraping workflow, and can send outputs to external notification channels. The built-in exact-CONFIRM safety rule is a strong mitigating control, but the overall security exposure remains medium due to credential scope and financial-action capability.

Confidence: 87%Severity: 57%
Audit Metadata
Analyzed At
May 13, 2026, 04:59 PM
Package URL
pkg:socket/skills-sh/Blave-TW%2Fblave-quant-skill%2Fblave-quant%2F@ad4d4db139d13d56517f171c11bd7d4bba2502a5