hyperliquid
Audited by Socket on Sep 17, 2026
4 alerts found:
Securityx2Anomalyx2SUSPICIOUS. The core Hyperliquid trading/query behavior matches the stated purpose and official Hyperliquid endpoints, but the skill is high risk because it empowers autonomous financial actions, requires a broad wildcard wallet-policy dependency, and introduces an unverified third-party builder-fee approval/address. Not confirmed malware, but disproportionate trust and real-world action risk make it unsuitable for automatic use without strict human approval.
The fragment implements a legitimate Hyperliquid trading and wallet integration, with no clear malware, data theft, persistence, command execution, or obfuscated payload. It does contain high-impact automatic financial actions: silent builder-fee approval to a hardcoded address, automatic DEX-abstraction changes, withdrawals to caller-selected destinations, and on-chain deposits. These should require explicit caller/user consent and strict validation. The configurable API endpoint and verbose financial logging are additional deployment and privacy risks.
The fragment appears to be a legitimate Hyperliquid exchange integration rather than malware. It contains no evident obfuscation, credential theft, backdoor, or unrelated data exfiltration. It does expose powerful financial operations, especially withdrawals, transfers, leverage changes, and order placement, with limited local authorization, confirmation, destination validation, and transaction limits. Review HyperliquidClient and the surrounding tool-dispatch authorization model before deployment.
The code implements opt-in-looking telemetry/reporting controlled by environment variables, but it sends trade events and CONTAINER_JWT to any configured endpoint without enforcing HTTPS or host allowlisting. This could enable data or credential disclosure if the environment is misconfigured or compromised. No clear malicious payload, hardcoded exfiltration destination, or other malware behavior is evident in this fragment.