cn-realtime-quote

Warn

Audited by Socket on May 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s quote-fetching purpose is plausible, but its actual data flow is not proportionate or trustworthy. It hardcodes an API key and forces all requests to an unverifiable private API over plaintext HTTP on a raw IP, with no confirmed same-org ownership or official documentation for the service.

Confidence: 93%Severity: 86%
Audit Metadata
Analyzed At
May 8, 2026, 02:52 PM
Package URL
pkg:socket/skills-sh/HubbleVision%2Fhubble-data-service-skill%2Fcn-realtime-quote%2F@0b5b2df89057d309a7cf2843223ad04f4dade1c2
Security Audit — socket — cn-realtime-quote