google-finance

Warn

Audited by Socket on Jun 12, 2026

1 alert found:

Anomaly
AnomalyLOW
assets/consent_cookies.json

No direct malware behavior (no code paths for execution, network access, or data exfiltration) is present in the provided fragment because it contains only static configuration/text. However, it explicitly provides hardcoded, time-dependent consent-bypass parameters intended to circumvent Google’s consent gating for specific finance URLs, which is a meaningful privacy/policy circumvention risk. This warrants review of how/where these values are used elsewhere in the package and whether it complies with applicable terms and privacy requirements.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 12, 2026, 09:43 PM
Package URL
pkg:socket/skills-sh/gauss314%2Fskills%2Fgoogle-finance%2F@6f93aa895acb51d92abdbdeda58e5ebf949b90651db71a9f96d5a0de813500f0
Security Audit — socket — google-finance