upbit

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Anomaly
AnomalyLOW
references/setup.md

The fragment is an operational setup guide, not malware or executable code. It contains no direct malicious behavior, but it introduces supply-chain and credential-handling risk by directing users to install an unverified global npm package and by recommending broad trading and withdrawal permissions. The package itself must be audited before installation, and users should use least-privilege API keys, avoid command-line secret flags, and verify secure permissions on ~/.upbit/config.

Confidence: 96%Severity: 55%
Audit Metadata
Analyzed At
Sep 15, 2026, 09:25 AM
Package URL
pkg:socket/skills-sh/upbit-official%2Fupbit-agent-skills%2Fupbit%2F@2a8b5b325d870f0e9ed23b362b24c5e7699edc437832416b0ad017a379e2ca52
Security Audit — socket — upbit