jupiter

Warn

Audited by Socket on Sep 17, 2026

1 alert found:

Anomaly
AnomalyLOW
_trade_report.py

The code implements opt-in-looking telemetry/reporting controlled by environment variables, but it sends trade events and CONTAINER_JWT to any configured endpoint without enforcing HTTPS or host allowlisting. This could enable data or credential disclosure if the environment is misconfigured or compromised. No clear malicious payload, hardcoded exfiltration destination, or other malware behavior is evident in this fragment.

Confidence: 97%Severity: 58%
Audit Metadata
Analyzed At
Sep 17, 2026, 04:29 AM
Package URL
pkg:socket/skills-sh/starchild-ai-agent%2Fofficial-skills%2Fjupiter%2F@efe0ca2803b0c7eebb064b92bdb56b5b8073f5be19c83106f807873e3ec7e01c
Security Audit — socket — jupiter