@349/lighter-dex

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is purpose-aligned and uses vendor-documented install paths and API domains, so it does not look like credential harvesting or a deceptive supply-chain lure. However, it grants an AI agent direct leveraged trading capability, includes transitive skill loading guidance, and relies on local helper scripts not shown here; that makes it a high security-risk financial-action skill despite limited evidence of malware.

Confidence: 90%Severity: 78%
Audit Metadata
Analyzed At
Mar 18, 2026, 03:13 AM
Package URL
pkg:socket/skills-sh/Starchild-ai-agent%2Fcommunity-skills%2F349lighter-dex%2F@1735fa1d771f2b5f085301e38d0b50cd6710da13
Security Audit — socket — @349/lighter-dex