quantai-service

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s quant-research behavior is internally coherent, but it relies on an unverifiable third-party service hosted at a raw AWS IP over plain HTTP. That creates meaningful confidentiality and integrity risk for uploaded plugin/strategy code and for downloaded logs/code that the agent then acts upon. No direct credential harvesting or malware is evident, but the transport and ownership model are not trustworthy enough to consider benign.

Confidence: 86%Severity: 78%
Audit Metadata
Analyzed At
Mar 15, 2026, 08:55 AM
Package URL
pkg:socket/skills-sh/varsity-tech-product%2Fotto-skills%2Fquantai-service%2F@10339228bd4193001a978998515c719560019578