curve-gauge-yield-trader

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s capabilities largely match its stated DeFi trading purpose, so this is not confirmed malware, but it is a high-risk agent skill because it authorizes autonomous real-money blockchain actions, recurring scheduled execution, and use of sensitive wallet/API credentials. Main concern is scope and autonomy, not hidden exfiltration.

Confidence: 87%Severity: 86%
Audit Metadata
Analyzed At
Mar 21, 2026, 02:46 AM
Package URL
pkg:socket/skills-sh/serenorg%2Fseren-skills%2Fcurve-gauge-yield-trader%2F@c943a65102563ba702f491f6046e52041942ad17