sec-edgar-skill

Fail

Audited by Socket on Mar 11, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The SEC EDGAR Skill is largely benign and consistent with its stated purpose. It uses an official Python package from a reputable registry to access public SEC filings, requires only legitimate identification with EdgarTools, and fetches data for analysis rather than exfiltrating user data. The main risk is typical data transfer of potentially large filings (via filing.text()) and ensuring users are aware of token/length costs when requesting large documents. Overall, the footprint aligns with a legitimate developer tool for SEC filing analysis without evident credential harvesting or covert data leakage.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 11, 2026, 04:24 AM
Package URL
pkg:socket/skills-sh/kwp-lab%2Ffinance-agent-skills%2Fsec-edgar-skill%2F@58f343bd0417b761ec678342efed6b27bf46b7c8