trading-strategy

Warn

Audited by Socket on Mar 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core trading-analysis purpose is plausible, but the skill reaches into risky territory by fetching arbitrary external content, requesting user auth headers for paid sources, and enabling scheduled execution near real-world trading workflows. There is no clear malware payload or malicious exfiltration endpoint, but the credential handling and prompt-injection exposure are disproportionate enough to raise medium-high security concerns.

Confidence: 84%Severity: 68%
Audit Metadata
Analyzed At
Mar 14, 2026, 10:08 PM
Package URL
pkg:socket/skills-sh/Starchild-ai-agent%2Fofficial-skills%2Ftrading-strategy%2F@1fe8354ae87ebc937f6981312359a1953de9e618