htx-spot-trading
Warn
Audited by Socket on May 7, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
Purpose and capabilities are aligned for an HTX trading skill, and the required user confirmation is a meaningful safeguard. However, the skill’s core execution path relies on an undocumented external `htx-cli` binary that receives HTX API credentials and can place real-money trades, so this is best classified as SUSPICIOUS/HIGH-RISK rather than benign.
Confidence: 84%Severity: 88%
Audit Metadata