google-finance
Warn
Audited by Socket on Jun 12, 2026
1 alert found:
AnomalyAnomalyassets/consent_cookies.json
LOWAnomalyLOW
assets/consent_cookies.json
No direct malware behavior (no code paths for execution, network access, or data exfiltration) is present in the provided fragment because it contains only static configuration/text. However, it explicitly provides hardcoded, time-dependent consent-bypass parameters intended to circumvent Google’s consent gating for specific finance URLs, which is a meaningful privacy/policy circumvention risk. This warrants review of how/where these values are used elsewhere in the package and whether it complies with applicable terms and privacy requirements.
Confidence: 100%Severity: 60%
Audit Metadata