edge-hint-extractor

Warn

Audited by Socket on Jun 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core skill is coherent and mostly local, but the optional --llm-ideas-cmd mode expands the trust boundary to arbitrary external code without provenance or verification. Not malicious on its face, yet the external CLI hook creates medium security risk disproportionate to a simple hint-extraction workflow when safer file-based augmentation is already supported.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 15, 2026, 01:21 PM
Package URL
pkg:socket/skills-sh/Fabio29T%2FTrading-Skills%2Fedge-hint-extractor%2F@02945ad587116a41e30cac2feebb202d5aeb1f3c9a386bf7c0c02db858955240
Security Audit — socket — edge-hint-extractor