trader-signal

Warn

Audited by Socket on Jun 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose matches its capabilities, but it relies on runtime installation/execution of an unpinned third-party trading CLI with native components and imperfect release hygiene. No clear credential theft or malicious exfiltration is shown, but the supply-chain footprint and financial decision support make it medium-high risk.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 13, 2026, 01:25 PM
Package URL
pkg:socket/skills-sh/ruvnet%2Fclaude-flow%2Ftrader-signal%2F@b6f8d8b44040b403e2acfd5483fc06109d2e3b7af86315fb103a0174b69da551
Security Audit — socket — trader-signal