roach-strategy

Warn

Audited by Socket on May 5, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally aligned with an automated trading strategy, and its installs appear same-org/official rather than obviously malicious. However, it performs autonomous real-money trading, suppresses routine visibility with NO_REPLY, uses unpinned raw GitHub downloads, and includes a pattern that can forward API credentials into downloaded code; this makes it high security risk without enough evidence for confirmed malware.

Confidence: 86%Severity: 78%
Audit Metadata
Analyzed At
May 5, 2026, 04:02 AM
Package URL
pkg:socket/skills-sh/Senpi-ai%2Fsenpi-skills%2Froach-strategy%2F@8834fa05d029a506301baa7b0564f6bcde830bc0