hummingbot-deploy

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: The skill is broadly aligned with its stated Hummingbot deployment purpose and uses verifiable same-org repositories, so this is not confirmed malware. Risk remains medium because it executes unpinned remote scripts, forwards credentials to a fetched installer, and installs another skill, all in service of infrastructure that can later automate trading actions.

Confidence: 84%Severity: 62%
Audit Metadata
Analyzed At
Mar 18, 2026, 04:49 PM
Package URL
pkg:socket/skills-sh/hummingbot%2Fskills%2Fhummingbot-deploy%2F@29f020d0cf4514af7a6789ff2290e00168548a41