quant-buddy-skill
Warn
Audited by Socket on Sep 17, 2026
1 alert found:
AnomalyAnomalyscripts/formula_package.py
LOWAnomalyLOW
scripts/formula_package.py
The code is primarily a formula-package API client with expected credential persistence and session-aware HTTP communication. No clear malware, exfiltration logic, obfuscation, command execution, or backdoor behavior is present. The main security issue is unsanitized package_id use in local file paths, enabling potential path traversal and unauthorized local file access or overwrite if attacker-controlled values reach these commands. The fixed temporary output file is a secondary local information-disclosure/race concern. The fragment also appears syntactically incomplete at the end.
Confidence: 97%Severity: 62%
Audit Metadata