stablecoin-market-brief

Warn

Audited by Socket on May 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core market-data functionality is well aligned and uses Barker's official public API with no credential collection, so the main behavior is benign. The concern is the auto-injected updater: it checks a mutable GitHub raw file and may trigger transitive `npx skills add` installation through a third-party Skills toolchain, which is unnecessary for answering stablecoin market questions and increases supply-chain risk.

Confidence: 88%Severity: 56%
Audit Metadata
Analyzed At
May 14, 2026, 05:31 AM
Package URL
pkg:socket/skills-sh/okx%2Fplugin-store%2Fstablecoin-market-brief%2F@6c1412cdba03a72f79c82024f225b90abdb602ed
Security Audit — socket — stablecoin-market-brief