portfolio-manager
Audited by Socket on Mar 9, 2026
1 alert found:
Obfuscated FileThe skill presents a coherent and proportionate footprint for a portfolio management tool that relies on Alpaca MCP Server data plus enrichment from market data sources to deliver asset allocation, diversification, risk, performance, and rebalancing guidance, culminating in a markdown portfolio report. The approach is appropriate for legitimate investment tooling. However, the integration of external data sources and the generation of stored reports introduce data provenance, privacy, and access-control considerations that should be explicitly addressed. No direct credential harvesting or suspicious download/execution patterns are evident in the described workflow, but explicit data-handling policies, secure storage for reports, and consent disclosures are advisable to strengthen security posture.