fiat

Warn

Audited by Socket on May 20, 2026

1 alert found:

Anomaly
AnomalyLOW
references/sapi-endpoints.md

The skill is mostly aligned with its stated Binance fiat purpose and routes data only to the official Binance API, so it is not malware. Risk comes from its credential-handling design: automatic secret retrieval from multiple local files, optional use without per-action confirmation, and storing new credentials in TOOLS.md are broader and less controlled than necessary. Overall this is suspicious-but-purpose-consistent, with medium security risk driven by secret access patterns rather than exfiltration behavior.

Confidence: 89%Severity: 56%
Audit Metadata
Analyzed At
May 20, 2026, 06:07 AM
Package URL
pkg:socket/skills-sh/npc-live%2Fclawfirm%2Ffiat%2F@46f57dd58a2901c262050d5804a6de56e08d8058
Security Audit — socket — fiat