starter-coach

Warn

Audited by Socket on May 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS rather than malicious. The skill is internally coherent and the OnchainOS dependency appears legitimately tied to OKX, but it enables autonomous or semi-autonomous crypto trading, generates executable bot code, and can execute real-money swaps through a wallet-linked CLI. Same-org provenance reduces supply-chain concern, yet the real-world financial action scope keeps overall risk high.

Confidence: 88%Severity: 79%
Audit Metadata
Analyzed At
May 7, 2026, 04:06 AM
Package URL
pkg:socket/skills-sh/okx%2Fplugin-store%2Fstarter-coach%2F@63a618fc7d3dabfcb95e90c278b4daa8fdff3450