trader-risk

Warn

Audited by Socket on May 7, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose and capabilities mostly align, but it relies on unpinned npm/npx execution of a not-fully-verified third-party trading CLI. No clear credential theft or exfiltration is present, yet the supply-chain risk is substantial enough to treat this as medium/high security risk rather than benign.

Confidence: 80%Severity: 68%
Audit Metadata
Analyzed At
May 7, 2026, 03:19 PM
Package URL
pkg:socket/skills-sh/ruvnet%2Fruflo%2Ftrader-risk%2F@7f2063e0082c402cb87ca520b151102659b8486d