htx-spot-trading

Warn

Audited by Socket on May 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Purpose and capabilities are aligned for an HTX trading skill, and the required user confirmation is a meaningful safeguard. However, the skill’s core execution path relies on an undocumented external `htx-cli` binary that receives HTX API credentials and can place real-money trades, so this is best classified as SUSPICIOUS/HIGH-RISK rather than benign.

Confidence: 84%Severity: 88%
Audit Metadata
Analyzed At
May 7, 2026, 04:44 AM
Package URL
pkg:socket/skills-sh/htx-exchange%2Fhtx-skills-hub%2Fhtx-spot-trading%2F@5267be078d3f62539b1811080eb4306f0e2a2584