vulture-strategy
Warn
Audited by Socket on May 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is coherent for an automated trading bot and the Senpi GitHub source is same-org, so this is not clearly malware. However, it provisions autonomous leveraged crypto trading with scheduled execution, which is inherently high risk, and its install path uses unpinned remote downloads plus an external OpenClaw CLI.
Confidence: 87%Severity: 78%
Audit Metadata