tase-stock-analysis

Warn

Audited by Socket on Apr 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s stated purpose is legitimate and internally consistent, but its optional live-data path relies on an unpinned GitHub-installed MCP server whose provenance was not verified and to which it forwards a TASE API key. That makes the core concern install trust and credential forwarding rather than confirmed malicious behavior.

Confidence: 86%Severity: 84%
Audit Metadata
Analyzed At
Apr 14, 2026, 11:13 AM
Package URL
pkg:socket/skills-sh/skills-il%2Ftax-and-finance%2Ftase-stock-analysis%2F@a7df2f8ba0cb058b2e7a195e3b9b7f7acec76088