toss-securities
Warn
Audited by Gen Agent Trust Hub on May 12, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to install a third-party CLI tool by tapping an external Homebrew repository:
brew tap JungHoonGhae/tossinvest-cli. - [REMOTE_CODE_EXECUTION]: The skill installs and executes the
tossctlbinary downloaded from an unverified personal GitHub repository. This tool is granted access to the user's Toss Securities session and sensitive financial data. - [COMMAND_EXECUTION]: The skill performs multiple shell command executions to retrieve financial information, such as
tossctl account summary,tossctl portfolio positions, andtossctl orders list. - [REMOTE_CODE_EXECUTION]: The skill uses a Node.js package wrapper
toss-securitiesto programmatically interact with the financial data, introducing an additional dependency layer.
Audit Metadata