us-kline

Warn

Audited by Socket on May 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose is plausible, but the actual data flow is not trustworthy: all requests are forced to an unverifiable private service on a raw IP over plain HTTP, with a hardcoded API key embedded in the skill. The local install step is benign, but the runtime network and credential handling create high security risk and weak data-flow integrity.

Confidence: 94%Severity: 86%
Audit Metadata
Analyzed At
May 8, 2026, 02:52 PM
Package URL
pkg:socket/skills-sh/HubbleVision%2Fhubble-data-service-skill%2Fus-kline%2F@219d70b14805b71aeb12124f019cb8856a92521e