Shell command execution detected (child_process).
Critical
- Code
- suspicious.dangerous_exec
- Location
- scripts/tests/run_worker_once.js:17
Security audit
Security checks across malware telemetry and agentic risk
This is a disclosed Upbit trading automation skill that can place real orders, but its code and documentation are coherent with that purpose and do not show hidden exfiltration or unrelated behavior.
Install only if you intend to run an automated trading bot. Start with execution.dryRun=true, use minimal-permission Upbit API keys from the OpenClaw secret store, avoid storing keys in config.json, review the budget and maxPositions settings, and monitor account activity closely before enabling real trading.
64/64 vendors flagged this skill as clean.
Detected: suspicious.dangerous_exec, suspicious.exposed_secret_literal