future-predictor

Warn

Audited by Socket on May 9, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
README.md

No actual code fragment was provided—only project description text. There is no direct evidence of malware. However, the described intended behavior includes reading sensitive local artifacts (IDE open files and bash history), which is a high-risk design area if the implementation sends that data off-host or logs it insecurely. Review the real implementation for network/telemetry usage and data handling controls.

Confidence: 32%Severity: 45%
AnomalyLOW
SKILL.md

SUSPICIOUS. The core purpose is coherent with reading git diff, but the skill's footprint expands to IDE open files and bash history, which is broader and more privacy-invasive than necessary. There are no external installs, remote endpoints, or clear exfiltration paths, so this is not malicious, but it is medium risk due to disproportionate local data access.

Confidence: 89%Severity: 53%
Audit Metadata
Analyzed At
May 9, 2026, 04:29 AM
Package URL
pkg:socket/skills-sh/mphinance%2Falpha-skills%2Ffuture-predictor%2F@2c081a63696fe6285ebebdbe09919be01592e6b9
Security Audit — socket — future-predictor