senpi-strategy-ops

Warn

Audited by Socket on Aug 14, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s capabilities mostly match its stated purpose, but that purpose itself is high-impact live trading. Main concerns are autonomous financial actions and reliance on an externally installed, unpinned runtime plugin that receives auth-backed operations; data flows otherwise look consistent with Senpi/OpenClaw strategy management rather than obvious credential harvesting.

Confidence: 86%Severity: 82%
AnomalyLOW
scripts/_fetch.py

No overt malware behavior (exfiltration/backdoor/reverse shells/persistence) is evident in the provided fragment. However, the module performs a high-impact supply-chain action: it discovers and downloads arbitrary blob content from a specified GitHub repo/ref under strategies/<strategy_id>/ and writes those bytes to local disk with only a location-based traversal guard (dest_root escape prevention) and no integrity/authenticity verification. If attacker influence exists over repo/ref/strategy_id or the upstream content, this can enable malicious payload delivery via the persisted files.

Confidence: 62%Severity: 56%
Audit Metadata
Analyzed At
Aug 14, 2026, 10:51 PM
Package URL
pkg:socket/skills-sh/senpi-ai%2Fsenpi-skills%2Fsenpi-strategy-ops%2F@6e27c64a119b2431232cea3430346f37dfa5b7c3e71932455c222a6138f977d6
Security Audit — socket — senpi-strategy-ops