trader-cloud-backtest

Warn

Audited by Socket on May 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s core purpose is coherent, but its footprint is broader than ideal: it forwards Anthropic-key-backed operations through third-party `claude-flow` wrappers, installs an unpinned npm CLI in the remote container, and enables unrestricted-network cloud execution. This looks more like a risky third-party orchestration skill than confirmed malware.

Confidence: 84%Severity: 68%
Audit Metadata
Analyzed At
May 20, 2026, 10:54 AM
Package URL
pkg:socket/skills-sh/ruvnet%2Fruflo%2Ftrader-cloud-backtest%2F@77ec058fb4c05f54f28731e300775563539aae99
Security Audit — socket — trader-cloud-backtest