leapcat-ipo

Warn

Audited by Socket on Mar 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose matches the commands, but the skill's trust model is weak: it centers on an unverifiable `leapcat` binary that handles authentication and real financial transactions. Because the CLI provenance could not be verified and it receives credentials while enabling IPO subscribe/cancel actions, the skill presents high security risk even without confirmed malware.

Confidence: 86%Severity: 88%
Audit Metadata
Analyzed At
Mar 31, 2026, 11:34 PM
Package URL
pkg:socket/skills-sh/leapcat-ai%2Fleapcat-skills%2Fleapcat-ipo%2F@d9f1e53520fa861822d4cafc3374b8b06f6ed535
Security Audit — socket — leapcat-ipo