company-research-analyst

Warn

Audited by Socket on Apr 25, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

该技能目的与能力总体一致,主要用于证券研究写作,不像凭据窃取或明显恶意技能。但它高度依赖未完全可验证的下游 skills,并会处理不受信外部内容后写入本地文件,存在中等安全风险,尤其是转移信任链与间接提示注入风险。

Confidence: 82%Severity: 62%
Audit Metadata
Analyzed At
Apr 25, 2026, 03:23 PM
Package URL
pkg:socket/skills-sh/rectified-flow%2Fincite%2Fcompany-research-analyst%2F@1f805dbab0e3c3213d335fd7264bb5804110d307