vulture-strategy

Warn

Audited by Socket on May 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is coherent for an automated trading bot and the Senpi GitHub source is same-org, so this is not clearly malware. However, it provisions autonomous leveraged crypto trading with scheduled execution, which is inherently high risk, and its install path uses unpinned remote downloads plus an external OpenClaw CLI.

Confidence: 87%Severity: 78%
Audit Metadata
Analyzed At
May 15, 2026, 10:52 AM
Package URL
pkg:socket/skills-sh/Senpi-ai%2Fsenpi-skills%2Fvulture-strategy%2F@d21a0c99352708cc59c686a3c07a2397d9c0ad33
Security Audit — socket — vulture-strategy