finicity
Warn
Audited by Socket on Apr 29, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill's basic Finicity purpose is plausible, and the CLI install source is an official npm package, but the real integration is mediated through Membrane rather than directly with Finicity. That intermediary auth and proxy model expands trust, forwards financial-data access through a third party, and is only partially aligned with the stated single-service purpose.
Confidence: 84%Severity: 66%
Audit Metadata