xxyy-trade

Warn

Audited by Socket on Jul 9, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is broadly aligned with its stated purpose and uses same-org official endpoints, so it is not malware and not a supply-chain lure. However, it gives the agent high-impact crypto trading powers, routes a non-read-only wallet-authorizing API key to a custodial service, and mixes untrusted market/social content with action capability; this makes the skill high risk even though the data flow appears official.

Confidence: 88%Severity: 83%
SecurityMEDIUM
skills/xxyy-trade/SKILL.md

SUSPICIOUS. The skill is purpose-aligned and does not show malware-like installers or obvious credential exfiltration to third parties, but it enables real financial transactions with a single high-privilege API key, supports long-running automated scans, and allows override of the API base URL that could redirect credentials. This is a coherent but inherently high-impact trading skill with medium-high security risk rather than confirmed malware.

Confidence: 88%Severity: 76%
Audit Metadata
Analyzed At
Jul 9, 2026, 07:11 PM
Package URL
pkg:socket/skills-sh/jimmy-holiday%2Fxxyy-trade-skill%2Fxxyy-trade%2F@2cc0ff3d95583579f3e1b2b4a2c8429342bb0784
Security Audit — socket — xxyy-trade