blave-quant

Fail

Audited by Socket on Mar 11, 2026

2 alerts found:

Obfuscated FileAnomaly
Obfuscated FileHIGH
SKILL.md

The skill's footprint is broadly coherent with its stated purpose: it orchestrates a Blave CLI to fetch market/news data and account information. However, there are minor security gaps: potential command-injection risk if inputs are unsanitized, and credential handling for Hyperliquid access is not described. No unmanaged binaries or external code downloads are evident. Overall risk is low-to-moderate (benign-to-suspicious), with recommended tightening around input sanitization and explicit credential management practices.

Confidence: 98%
AnomalyLOW
README.md

The installation guidance presents operational risks rather than explicit malicious code. Key concerns are credential handling, editable installs, privileged system modifications, and missing integrity checks. Recommend trusted sourcing, minimizing privileged steps, securing credentials, and implementing verifiable installation practices before use.

Confidence: 68%Severity: 65%
Audit Metadata
Analyzed At
Mar 11, 2026, 01:17 PM
Package URL
pkg:socket/skills-sh/blave-tw%2Fblave-quant-skill%2Fblave-quant%2F@7900828dada99c64777a8509944d04d8accd1640