stock-analysis

Warn

Audited by Socket on Apr 6, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core stock-analysis workflow is broadly coherent and mostly benign, with normal local storage and public-data lookups. The main security concern is the optional Twitter/X integration: it installs a third-party npm CLI and forwards session tokens via .env, which is a meaningful credential-forwarding risk disproportionate to the skill’s primary purpose.

Confidence: 84%Severity: 68%
Audit Metadata
Analyzed At
Apr 6, 2026, 03:35 AM
Package URL
pkg:socket/skills-sh/LeoYeAI%2Fopenclaw-master-skills%2Fstock-analysis%2F@98588ace5ea0a0a68bfd9807eb2cfe924db6392c