crible-cli

Warn

Audited by Socket on Jul 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose and capabilities mostly align for a stock screener/data-pipeline tool, and it appears to use same-source install instructions from the project’s own GitHub repo. The main concern is install and execution trust: the core tool is installed from an unpinned GitHub source outside an official package registry, and the skill has a broad operational footprint with multiple networked data-ingestion paths. No clear credential theft, covert exfiltration, or confirmed malware behavior is present.

Confidence: 82%Severity: 72%
Audit Metadata
Analyzed At
Jul 17, 2026, 10:43 AM
Package URL
pkg:socket/skills-sh/maxgfr%2Fcrible%2Fcrible-cli%2F@37402a71e5ff15342616a747c034dee35b719c5041c132157a994f3dbadc3508
Security Audit — socket — crible-cli