crible-cli

Warn

Audited by Socket on Sep 10, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's capabilities fit its stated stock-screening purpose and the data flows are mostly coherent and keyless, but it asks the agent/user to execute unpinned code from a personal GitHub repository and then rely on that binary for CLI and MCP usage. This is a supply-chain risk rather than confirmed malware; no credential harvesting, covert exfiltration, or malicious pre-execution behavior is evident.

Confidence: 91%Severity: 72%
Audit Metadata
Analyzed At
Sep 10, 2026, 06:04 AM
Package URL
pkg:socket/skills-sh/maxgfr%2Fcrible%2Fcrible-cli%2F@f34f65030e863835c24366eab82112c556dacba0b9419a4f7bda82ab0478ad4b
Security Audit — socket — crible-cli