datapack-builder

Fail

Audited by Socket on Feb 25, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The specification itself is benign and functionally coherent for producing standardized financial data packs. The main security concerns are operational/supply-chain: (1) use of an external xlsx skill and any remote web/MCP fetch capability can forward sensitive data unless the runtime enforces strict controls; (2) lack of specified secure auth and least-privilege patterns for MCP/internal server access risks credential exposure; and (3) explicit requirement to copy source text/page references into outputs increases exfiltration risk. I judge this as not overtly malicious but carrying a moderate supply-chain/data-exposure risk that requires runtime controls and explicit handling of credentials and output destinations.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 25, 2026, 02:28 AM
Package URL
pkg:socket/skills-sh/anthropics%2Ffinancial-services-plugins%2Fdatapack-builder%2F@3fea379864b075c8414795c967ddeac0c514e24b