xxyy-trade
Audited by Socket on Jul 9, 2026
2 alerts found:
Securityx2SUSPICIOUS: the skill is broadly aligned with its stated purpose and uses same-org official endpoints, so it is not malware and not a supply-chain lure. However, it gives the agent high-impact crypto trading powers, routes a non-read-only wallet-authorizing API key to a custodial service, and mixes untrusted market/social content with action capability; this makes the skill high risk even though the data flow appears official.
SUSPICIOUS. The skill is purpose-aligned and does not show malware-like installers or obvious credential exfiltration to third parties, but it enables real financial transactions with a single high-privilege API key, supports long-running automated scans, and allows override of the API base URL that could redirect credentials. This is a coherent but inherently high-impact trading skill with medium-high security risk rather than confirmed malware.