analyze-stock

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose and visible capabilities mostly align with stock research/report generation, and it does not request credentials or route data through suspicious intermediaries. The main concern is install/execution trust: the unpinned `npx -y md-to-pdf` fallback executes remote npm code at runtime, and the referenced local `data_fetcher.py` cannot be reviewed here. This is better classified as medium supply-chain and prompt-injection risk than malicious behavior.

Confidence: 89%Severity: 58%
Audit Metadata
Analyzed At
Mar 13, 2026, 06:08 PM
Package URL
pkg:socket/skills-sh/jssfy%2Fk-skills%2Fanalyze-stock%2F@683e7e2b71da92c4615ff1fe8ea38b76e75512f5