upbit

Warn

Audited by Socket on May 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s capabilities fit a crypto-exchange integration, but its trust model is incomplete: it asks the agent to use a local `upbit` binary and forward exchange credentials without providing verifiable installer provenance in the supplied material. Real-money actions are in scope and partly mitigated by a CONFIRM step, while `--base-url` also allows authenticated traffic to be redirected. Main concern is unverifiable external CLI trust plus credential forwarding, not confirmed malware.

Confidence: 84%Severity: 83%
Audit Metadata
Analyzed At
May 7, 2026, 01:32 AM
Package URL
pkg:socket/skills-sh/upbit-official%2Fupbit-agent-skills%2Fupbit%2F@e661c464d2be1f720f10c0b6e73616d599146144