gate-news-eventexplain
Audited by Socket on Mar 12, 2026
1 alert found:
Obfuscated FileThe gate-news-eventexplain skill presents a coherent, analysis-focused capability that aligns with its stated purpose of explaining price moves via event attribution. Its data flow relies on monitored, read-only MCP tools to fetch events, market snapshots, and on-chain data, followed by a structured attribution report. There are no evident insecure downloads or credential-forwarding patterns in the provided design. The risk surface is mainly around reliance on external data sources and the potential for misattribution if sources are unreliable, but there is no indication of deliberate credential harvesting, backdoor access, or autonomous world actions. Overall, the skill appears benign with moderate risk due to external data dependencies and the need for robust source attribution; securityRisk is moderate and warranted given the external API dependency surface.