blockfill-agent-execution

Warn

Audited by Socket on Aug 12, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

High-risk vulnerable skill. Its trading capability matches the stated purpose, but the footprint is risky: a bundled opaque executor binary receives exchange credentials, can take autonomous real-money trading actions, and the documented hardcoded qtex endpoint conflicts with the no-third-party-routing claim. Proxying through sc-vpn or arbitrary proxies further weakens data-flow integrity.

Confidence: 85%Severity: 90%
Audit Metadata
Analyzed At
Aug 12, 2026, 05:21 PM
Package URL
pkg:socket/skills-sh/starchild-ai-agent%2Fofficial-skills%2Fblockfill-agent-execution%2F@d468b942c7877910490ae0dda8a9b843b01fc1ff0b79a8c9a4189dc13c79c183
Security Audit — socket — blockfill-agent-execution