crible-cli
Warn
Audited by Socket on Jul 17, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s purpose and capabilities mostly align for a stock screener/data-pipeline tool, and it appears to use same-source install instructions from the project’s own GitHub repo. The main concern is install and execution trust: the core tool is installed from an unpinned GitHub source outside an official package registry, and the skill has a broad operational footprint with multiple networked data-ingestion paths. No clear credential theft, covert exfiltration, or confirmed malware behavior is present.
Confidence: 82%Severity: 72%
Audit Metadata