investment-intelligence

Fail

Audited by Socket on Feb 26, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

This skill specification describes legitimate investment-intelligence functionality and contains no direct signs of malware, hard-coded secrets, or execution chains. Primary concerns are operational: missing connector endpoint provenance, absent authentication/scoping guidance, no data-retention or PII-handling policies, and limited error/retry control. These gaps create a moderate security risk mostly centered on potential credential forwarding and data exfiltration if the agent/platform or connector implementation is not trusted. Recommendation: verify the connector implementation (endpoints, TLS certs, hosting), enforce least-privilege tokens, add explicit data-handling and redaction rules, and implement retry/backoff and logging/audit controls before enabling in sensitive environments.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 26, 2026, 09:09 PM
Package URL
pkg:socket/skills-sh/PrimaryLogic%2Fagent-skills%2Finvestment-intelligence%2F@546a3c32109a3f0a17522cdfa3e1dc5d02d5e10f