us-fundamental
Warn
Audited by Socket on May 6, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s stated purpose is coherent, but its actual data flow is not trustworthy: it routes requests to an undocumented raw-IP host over HTTP and hardcodes an API key in the prompt. This is disproportionate for a simple market-calendar/list lookup skill and creates meaningful credential exposure and response-integrity risk, though there is no clear evidence of confirmed malware or payload execution.
Confidence: 88%Severity: 71%
Audit Metadata