trading-research
Warn
Audited by Socket on Apr 11, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the core purpose is coherent, but the footprint is risky because the skill turns untrusted web research into executable trading code and likely runs it during backtests. Install trust is mostly benign from the provided evidence, but the combination of web ingestion, code generation, local execution, and financial-domain use makes this a high-risk skill even without confirmed malware or direct credential theft.
Confidence: 88%Severity: 74%
Audit Metadata