stock-analysis

Warn

Audited by Socket on Mar 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core stock-analysis workflow is broadly coherent and mostly benign, with normal local storage and public-data lookups. The main security concern is the optional Twitter/X integration: it installs a third-party npm CLI and forwards session tokens via .env, which is a meaningful credential-forwarding risk disproportionate to the skill’s primary purpose.

Confidence: 84%Severity: 68%
Audit Metadata
Analyzed At
Mar 16, 2026, 08:24 AM
Package URL
pkg:socket/skills-sh/kirkluokun%2Fawesome-a-stock-openclawskills%2Fstock-analysis%2F@00bdb54332bb4d8d68b315bca2cedbf145cf9198