quant-buddy-skill

Warn

Audited by Socket on Sep 17, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/formula_package.py

The code is primarily a formula-package API client with expected credential persistence and session-aware HTTP communication. No clear malware, exfiltration logic, obfuscation, command execution, or backdoor behavior is present. The main security issue is unsanitized package_id use in local file paths, enabling potential path traversal and unauthorized local file access or overwrite if attacker-controlled values reach these commands. The fixed temporary output file is a secondary local information-disclosure/race concern. The fragment also appears syntactically incomplete at the end.

Confidence: 97%Severity: 62%
Audit Metadata
Analyzed At
Sep 17, 2026, 06:06 AM
Package URL
pkg:socket/skills-sh/pseudo-longinus%2Fquant-buddy-skills%2Fquant-buddy-skill%2F@60d87a796a25ba331bcc61956ec22bd4847b122c0b8a433193fd4a808a8efc61
Security Audit — socket — quant-buddy-skill