roach-strategy
Warn
Audited by Socket on May 5, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally aligned with an automated trading strategy, and its installs appear same-org/official rather than obviously malicious. However, it performs autonomous real-money trading, suppresses routine visibility with NO_REPLY, uses unpinned raw GitHub downloads, and includes a pattern that can forward API credentials into downloaded code; this makes it high security risk without enough evidence for confirmed malware.
Confidence: 86%Severity: 78%
Audit Metadata