crypto-com-app

Warn

Audited by Socket on Apr 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Purpose and requested credentials are broadly consistent with a Crypto.com trading skill, and the network destination appears same-org. The main risk is not covert exfiltration but the skill’s ability to let an agent perform cryptocurrency trades and revoke keys, including optional auto-execution without per-trade confirmation. Treat as high security risk due to autonomous financial actions and moderate supply-chain opacity from runtime `npx` execution and unseen local scripts, but not confirmed malware.

Confidence: 86%Severity: 82%
Audit Metadata
Analyzed At
Apr 1, 2026, 08:51 PM
Package URL
pkg:socket/skills-sh/crypto-com%2Fcrypto-agent-trading%2Fcrypto-com-app%2F@d4e45744c1b732a4f334eecb5f23003a9dc995b7