Security audit
Sim Trade
Security checks across malware telemetry and agentic risk
Overview
The local simulator code is mostly straightforward, but the skill asks users to store full browser cookies or broker API tokens for external account access without clear scoping or a real implemented integration.
Using the local simulation and quote lookup appears reasonable. Treat the external-platform setup as high risk: do not paste full Cookies or broker tokens unless the provider clearly documents the exact access needed, where the credentials go, and how to revoke or delete them.
VirusTotal
63/63 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
