@349/binance
Warn
Audited by Socket on Mar 16, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill is purpose-aligned for Binance trading and uses a legitimate registry dependency, but it enables autonomous high-impact financial actions, persists install behavior, and requires exchange credentials for a bundled engine that was not provided for review. No clear malicious exfiltration is evident, but the real-world trading authority and partial trust gap make this a high-risk skill.
Confidence: 89%Severity: 76%
Audit Metadata