trader-explain

Warn

Audited by Socket on Jun 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s core behavior matches its stated trading-attribution purpose, but it relies on an unpinned external npm CLI invoked through Bash and may expose trading-signal data to that third-party code. Key-file access is purpose-consistent for signing, and no explicit off-platform exfiltration is described, so this is not confirmed malicious; the main issue is supply-chain and credential/data exposure risk from the external CLI dependency.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 13, 2026, 01:24 PM
Package URL
pkg:socket/skills-sh/ruvnet%2Fclaude-flow%2Ftrader-explain%2F@4b6c92097fff459b92f7c955960b25d6f8587bac6fc32d97f3c9d3f0a656d78e
Security Audit — socket — trader-explain