Description-Behavior Mismatch
Low
- Confidence
- 94% confidence
- Finding
- The README instructs users to execute a network-fetched shell script as part of setup, which creates a supply-chain risk: the remote content can change at any time and will execute with the user's privileges. In this specific skill, the risk is amplified because the same README later instructs users to configure a wallet private key, so a malicious or compromised script could steal credentials or alter trading behavior.
