korean-stock-search
Warn
Audited by Socket on Apr 8, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill's function is coherent as a Korean stock lookup tool, but its core design routes all queries through a third-party proxy instead of the official KRX API. That proxy-mediated data flow is the main concern: users must trust a non-official service that injects and manages the upstream API key and can observe or alter responses. No malware, installer, or credential theft behavior is shown, but the intermediary architecture makes this medium risk rather than benign.
Confidence: 87%Severity: 58%
Audit Metadata