portfolio-pulse
Warn
Audited by Socket on Aug 12, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core portfolio-monitoring behavior mostly matches the stated purpose, and the data flows appear centered on LLMQuant/Hermes rather than obvious attacker infrastructure. The main concerns are transitive skill installation, medium supply-chain trust from GitHub/third-party installer paths, and automated Telegram delivery of sensitive portfolio summaries.
Confidence: 84%Severity: 62%
Audit Metadata