openocean

Warn

Audited by Socket on Sep 17, 2026

3 alerts found:

SecurityAnomalyx2
SecurityMEDIUM
SKILL.md

BENIGN for purpose alignment and endpoint consistency, but HIGH security risk because it enables on-chain financial actions and token approvals through a wallet runtime. No clear malware or exfiltration signs are present in the provided skill text, yet the transactional authority makes misuse costly if invoked without careful confirmation.

Confidence: 87%Severity: 74%
AnomalyLOW
exports.py

No clear malware or covert exfiltration is present. The code performs legitimate but high-impact cryptocurrency trading operations. Security risk is concentrated in trusting API-supplied transaction parameters and granting MAX_UINT256 ERC-20 allowances to the returned router. Router address, chain ID, calldata, and allowance scope should be independently validated or constrained before wallet submission.

Confidence: 96%Severity: 68%
AnomalyLOW
_trade_report.py

The code implements opt-in-looking telemetry/reporting controlled by environment variables, but it sends trade events and CONTAINER_JWT to any configured endpoint without enforcing HTTPS or host allowlisting. This could enable data or credential disclosure if the environment is misconfigured or compromised. No clear malicious payload, hardcoded exfiltration destination, or other malware behavior is evident in this fragment.

Confidence: 97%Severity: 58%
Audit Metadata
Analyzed At
Sep 17, 2026, 04:29 AM
Package URL
pkg:socket/skills-sh/starchild-ai-agent%2Fofficial-skills%2Fopenocean%2F@f8e78c42ae6353ce20accd15658bbe4d565b6494224cea6a47b9fa7971b5ceef
Security Audit — socket — openocean