trader-cloud-backtest
Warn
Audited by Socket on May 20, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s core purpose is coherent, but its footprint is broader than ideal: it forwards Anthropic-key-backed operations through third-party `claude-flow` wrappers, installs an unpinned npm CLI in the remote container, and enables unrestricted-network cloud execution. This looks more like a risky third-party orchestration skill than confirmed malware.
Confidence: 84%Severity: 68%
Audit Metadata