iFinD-Finance-Data

Warn

Audited by Socket on May 9, 2026

1 alert found:

Security
SecurityMEDIUM
mcp_config.json

The provided fragment contains a hardcoded authentication secret (auth_token). While there is no executable logic here to prove malware, this is a significant supply-chain credential leakage risk; the token should be treated as compromised and rotated, and the secret should be removed from any distributed artifacts/history.

Confidence: 80%Severity: 70%
Audit Metadata
Analyzed At
May 9, 2026, 01:12 AM
Package URL
pkg:socket/skills-sh/JsonCodeChina%2Fwind-skills%2Fifind-finance-data%2F@edfd6afa56516a1b95f9b0572219f518a25f1565
Security Audit — socket — iFinD-Finance-Data