@3073/virtual-trading
Warn
Audited by Socket on Apr 22, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The skill is broadly consistent with its stated purpose, and the named endpoints/install source are mostly coherent with Virtual Protocol and Hyperliquid usage. The main concern is not hidden exfiltration but that the skill grants an AI agent autonomous high-impact capabilities: leveraged trading, withdrawals, and public posting using stored secrets. This makes it high risk even though it does not appear clearly malicious.
Confidence: 90%Severity: 78%
Audit Metadata