crible-cli
Warn
Audited by Socket on Sep 10, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill's capabilities fit its stated stock-screening purpose and the data flows are mostly coherent and keyless, but it asks the agent/user to execute unpinned code from a personal GitHub repository and then rely on that binary for CLI and MCP usage. This is a supply-chain risk rather than confirmed malware; no credential harvesting, covert exfiltration, or malicious pre-execution behavior is evident.
Confidence: 91%Severity: 72%
Audit Metadata