mcp-us-equities-intraday

Fail

Audited by Socket on Mar 9, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's stated purpose and its core capabilities align logically with intraday market data querying. However, the installation and configuration workflow rely on unverifiable binaries downloaded via curl from an untrusted, non-registry source, combined with an HTTP endpoint for configuration. Data flows themselves are typical for market data ingestion but are contingent on trusting the external rw tool and the remote server. Overall, the footprint is coherent with its purpose but carries substantial security risks due to supply-chain and transport-layer vulnerabilities. Treat as SUSPICIOUS with high risk of credential/data exposure if the tool or endpoints are compromised; mitigate by using signed, registry-distributed tooling, enforce TLS/HTTPS for all endpoints, and restrict data access to authenticated, auditable sources.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 9, 2026, 11:47 PM
Package URL
pkg:socket/skills-sh/zz3310969%2Fmax-skills%2Fmcp-us-equities-intraday%2F@a570c911d139219aa5d31a7bc2fa9831c8b1c14d