us-market

Warn

Audited by Socket on May 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s market-data purpose is coherent, but its runtime trust model is not: it hardcodes credentialed requests to an unverified private API on a raw IP over plain HTTP, with no verifiable publisher relationship or transport protection. This is not confirmed malware, but it is a high-risk data-flow and credential-handling pattern for an AI skill.

Confidence: 90%Severity: 82%
Audit Metadata
Analyzed At
May 8, 2026, 02:52 PM
Package URL
pkg:socket/skills-sh/HubbleVision%2Fhubble-data-service-skill%2Fus-market%2F@6d7c140a47a08b2cfb008b0d3ffd8f5e11b836dc