jquants-cli-usage

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill’s functionality matches a market-data CLI guide, and its data flows are mostly proportionate, but it relies on a `jquants` executable whose official provenance was not established in the supplied evidence. Because that CLI is also expected to receive API credentials, the mandatory unverifiable-binary override makes this high security risk despite limited signs of overtly malicious behavior.

Confidence: 79%Severity: 82%
Audit Metadata
Analyzed At
Apr 9, 2026, 02:03 AM
Package URL
pkg:socket/skills-sh/J-Quants%2Fjquants-cli%2Fjquants-cli-usage%2F@3f5445d0f3ec33d44ae2130e702c39dc1f232fe5