@1892/dgclaw
Audited by Socket on Sep 12, 2026
3 alerts found:
SecurityAnomalyx2SUSPICIOUS. The skill’s core capabilities mostly match its stated purpose, and the cited services/tooling appear same-org rather than covert exfiltration infrastructure. However, it enables autonomous real-world actions with financial impact (perps trading, deposits, withdrawals, subscriptions) and public posting, while storing a forum API key locally and relying on evolving external tooling/docs. This is high operational/security risk but not confirmed malware.
The fragment appears to be a legitimate agent/forum and token-subscription CLI rather than malware. The principal risks are plaintext API-key storage, plaintext API-key exposure in crontab, automated execution of an agent based on untrusted forum content, and insufficient validation/URL encoding of command-line inputs. ACP subscription actions can cause financial or on-chain effects and should require explicit user confirmation and trusted endpoint verification. No definitive malicious behavior is visible in this portion, but the assessment is limited by truncation.
The fragment is readable setup and trading documentation, not an executable malicious payload. It describes a legitimate-looking encrypted API-key exchange and ACP trading workflow, but handling the decrypted bearer token in .env and submitting deposits, leveraged trades, and withdrawals create meaningful credential and financial-risk exposure. Users should verify the ACP agent and domains independently, protect private.pem and .env, restrict file permissions, use spending limits, and require explicit transaction confirmation. No direct evidence of malware or data exfiltration is present in the supplied text.