trading-signals

Warn

Audited by Socket on Apr 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core signal-fetching purpose is coherent, but the skill overreaches by requiring operator registration, collecting personal details, and instructing the agent to star the publisher's repo on the user's behalf. The MCP/API data flows are first-party to x70.ai, so this is not confirmed malware, but the autonomous public action, third-party identity transfer, and transitive skill-install instructions make the footprint disproportionate to a simple trading-signals skill.

Confidence: 92%Severity: 78%
Audit Metadata
Analyzed At
Apr 8, 2026, 03:22 AM
Package URL
pkg:socket/skills-sh/roman-rr%2Ftrading-skills%2Ftrading-signals%2F@5a4b41350e123b05ea888cbdff061cdb01ae87ed