senpi-trading-runtime
Warn
Audited by Socket on May 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The skill is purpose-consistent for a trading runtime, and its main network flows appear to use official/local endpoints. However, it grants an AI agent the ability to execute real financial actions, read local trading credentials from disk/env, create strategy wallets, and operate long-running daemons; this makes it high security risk even without strong evidence of malware or credential exfiltration to unrelated parties.
Confidence: 89%Severity: 86%
Audit Metadata