gate-news-eventexplain

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The gate-news-eventexplain skill presents a coherent, analysis-focused capability that aligns with its stated purpose of explaining price moves via event attribution. Its data flow relies on monitored, read-only MCP tools to fetch events, market snapshots, and on-chain data, followed by a structured attribution report. There are no evident insecure downloads or credential-forwarding patterns in the provided design. The risk surface is mainly around reliance on external data sources and the potential for misattribution if sources are unreliable, but there is no indication of deliberate credential harvesting, backdoor access, or autonomous world actions. Overall, the skill appears benign with moderate risk due to external data dependencies and the need for robust source attribution; securityRisk is moderate and warranted given the external API dependency surface.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 01:01 PM
Package URL
pkg:socket/skills-sh/gate%2Fgate-skills%2Fgate-news-eventexplain%2F@faafd6a963009e12d98376160ecd1a30ba08bb7b