analyze-stock
Warn
Audited by Socket on Mar 13, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s purpose and visible capabilities mostly align with stock research/report generation, and it does not request credentials or route data through suspicious intermediaries. The main concern is install/execution trust: the unpinned `npx -y md-to-pdf` fallback executes remote npm code at runtime, and the referenced local `data_fetcher.py` cannot be reviewed here. This is better classified as medium supply-chain and prompt-injection risk than malicious behavior.
Confidence: 89%Severity: 58%
Audit Metadata