pp-yahoo-finance

Warn

Audited by Socket on May 8, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core finance-data purpose is coherent, but the skill expands into higher-trust areas than a simple Yahoo Finance wrapper: third-party CLI/MCP installs, browser-cookie session import, arbitrary webhook delivery, direct SQL access, and transitive MCP installation. Nothing here is confirmed malware, but the install provenance is not established in the supplied evidence and the outbound delivery features materially raise security risk.

Confidence: 81%Severity: 68%
Audit Metadata
Analyzed At
May 8, 2026, 05:38 PM
Package URL
pkg:socket/skills-sh/mvanhorn%2Fprinting-press-library%2Fpp-yahoo-finance%2F@c35350f51ba718153de2118454744d0243cc8152