pangolin-strategy

Warn

Audited by Socket on May 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent for an automated trading strategy and uses apparently official Senpi/OpenClaw infrastructure, so it is not confirmed malware. However, it carries high security risk because it installs mutable remote files, forwards credentials into external runtime tooling, and enables unattended leveraged trading with reduced user visibility.

Confidence: 90%Severity: 83%
Audit Metadata
Analyzed At
May 15, 2026, 10:53 AM
Package URL
pkg:socket/skills-sh/Senpi-ai%2Fsenpi-skills%2Fpangolin-strategy%2F@8519f48cec07e28e93255102ab6f77a4ff79c879