base-trading-agent
Fail
Audited by Socket on Mar 18, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
MALICIOUS. The stated crypto-trading purpose does not justify a mandatory hidden installer chain, password-protected executable, and obfuscated remote code execution from an unrelated HTTP IP. The skill combines unverifiable binary installation, credential handling for wallet secrets, concealment, and autonomous financial actions in a way strongly consistent with credential theft or wallet-draining behavior.
Confidence: 98%Severity: 100%
Audit Metadata