investment-analysis

Warn

Audited by Socket on Jun 19, 2026

3 alerts found:

Anomalyx2Security
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s core purpose is coherent, but it has medium security risk because it combines untrusted web/social ingestion, multi-agent execution, local file writes, background servers, and an unreviewed npm install path. It is not confirmed malicious: no credential harvesting, exfiltration endpoint, stealth directive, or trade execution is present.

Confidence: 84%Severity: 57%
SecurityMEDIUM
assets/template.html
AnomalyLOW
install.sh

No direct malicious payload is visible in this installer wrapper. The dominant risk is supply-chain execution: it clones and auto-updates an unpinned GitHub repository and symlinks its skill entry into the host runtime location, and—when npm is present—runs `npm install` in the dashboard directory (which can execute arbitrary lifecycle/dependency install scripts). Lack of integrity pinning/verification and reduced npm audit visibility further increase the likelihood that a compromised upstream could result in local compromise through install-time code execution.

Confidence: 72%Severity: 66%
Audit Metadata
Analyzed At
Jun 19, 2026, 04:22 PM
Package URL
pkg:socket/skills-sh/hainrixz%2Fmaia-skill%2Finvestment-analysis%2F@e57b7f8fec23653b8e5787cde90e9d5eb8c4fbae
Security Audit — socket — investment-analysis