leapcat-trading

Warn

Audited by Socket on Mar 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s trading functionality matches its stated purpose, but the core `leapcat` CLI is unverifiable and receives account authentication plus authority to execute real stock trades. Because this is an unknown binary performing high-impact financial actions, the skill carries high security risk even without confirmed malicious behavior.

Confidence: 86%Severity: 90%
Audit Metadata
Analyzed At
Mar 31, 2026, 11:34 PM
Package URL
pkg:socket/skills-sh/leapcat-ai%2Fleapcat-skills%2Fleapcat-trading%2F@a43c90be60ded39e107f196c1d48b7999e0d20f9
Security Audit — socket — leapcat-trading