trader-signal

Warn

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill attempts to install the neural-trader package from the NPM registry if it is not already available. It utilizes the --ignore-scripts flag, which is a positive security measure to prevent the execution of potentially malicious lifecycle scripts during installation; however, the package remains an external dependency from a source that is not pre-vetted.
  • [COMMAND_EXECUTION]: The skill uses npx to run the neural-trader engine with user-supplied ticker symbols and strategy names. This involves executing third-party logic within the local environment to perform data scanning and anomaly detection.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 13, 2026, 01:23 PM
Security Audit — agent-trust-hub — trader-signal