us-stock-analysis
Warn
Audited by Socket on Mar 2, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
This skill is coherent with its stated purpose: it instructs the agent to gather public market data and use local reference documents to produce stock analysis and reports. I found no evidence of malicious behavior, credential harvesting, download-and-execute chains, or routing data through suspicious intermediaries. The primary security consideration is the standard risk of processing untrusted external content (prompt-injection style) when pulling from web pages; operators should ensure the agent runtime sanitizes or treats external content as untrusted input and that the agent is not granted unnecessary filesystem/network privileges. Overall, the skill appears benign for its intended use.
Confidence: 75%Severity: 75%
Audit Metadata