@349/bybit
Warn
Audited by Socket on Mar 18, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The skill is purpose-aligned for Bybit trading and uses plausible official data flows, but it grants an AI agent the ability to perform high-impact financial trades with user credentials. Supply-chain risk is moderate due to unpinned CCXT installation, and overall risk is driven mainly by autonomous real-world trading capability rather than clear malware or credential theft.
Confidence: 89%Severity: 78%
Audit Metadata