portfolio

Warn

Audited by Socket on Mar 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill's purpose and read-only wallet-portfolio behavior are broadly aligned, but it delegates core functionality to an unpinned third-party npm CLI (`npx fibx@latest`) with undocumented provenance and auth/session handling. That makes it suspicious from a supply-chain and session-forwarding perspective, though not overtly malicious based on the provided content.

Confidence: 76%Severity: 56%
Audit Metadata
Analyzed At
Mar 19, 2026, 04:25 PM
Package URL
pkg:socket/skills-sh/Fibrous-Finance%2Ffibx-skills%2Fportfolio%2F@0193f627063dd20e605cf05c42fb455201e622e2