finflow

Warn

Audited by Socket on Apr 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The stated purpose broadly matches financial-data retrieval, but the skill’s footprint is larger than a simple quote/news helper. It installs an only weakly verifiable third-party CLI, reads or auto-extracts browser/Keychain cookies, and can perform authenticated portfolio changes. Data flows to the named finance platforms are plausible, but credential handling and account-action scope are disproportionate enough to warrant caution.

Confidence: 82%Severity: 72%
Audit Metadata
Analyzed At
Apr 20, 2026, 02:14 PM
Package URL
pkg:socket/skills-sh/rectified-flow%2Fincite%2Ffinflow%2F@2e7904b71290e640681f3176bee1fc1277368c0f