olive-portfolio-analysis

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill’s business logic is coherent for portfolio analysis and KYC-driven report generation, and there is no clear evidence of credential theft or overt exfiltration. However, it depends on external tooling that could not be independently verified from the provided evidence, especially the required genesis-mcp binary; that supply-chain trust gap makes the skill suspicious/high-risk rather than benign.

Confidence: 82%Severity: 78%
Audit Metadata
Analyzed At
Apr 22, 2026, 07:25 AM
Package URL
pkg:socket/skills-sh/oliveam%2Fagent-skills%2Folive-portfolio-analysis%2F@aed0d6bdda74d6bc9bebb99d6f7e6e42eabbc7ba