leapcat-portfolio

Warn

Audited by Socket on Mar 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The stated purpose and commands are coherent for a portfolio-view skill, but trust in the required `leapcat` CLI is not verifiable from the available evidence. Because the skill depends on an opaque external binary for authentication and financial data access, the main issue is supply-chain and data-handling risk rather than confirmed malicious behavior.

Confidence: 81%Severity: 72%
Audit Metadata
Analyzed At
Mar 31, 2026, 11:34 PM
Package URL
pkg:socket/skills-sh/leapcat-ai%2Fleapcat-skills%2Fleapcat-portfolio%2F@e48c3e060ce5a9d6bca9871ccc91964e50a2ca48
Security Audit — socket — leapcat-portfolio