trader-explain

Warn

Audited by Socket on May 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s core behavior matches its stated trading-attribution purpose, but it relies on an unpinned external npm CLI invoked through Bash and may expose trading-signal data to that third-party code. Key-file access is purpose-consistent for signing, and no explicit off-platform exfiltration is described, so this is not confirmed malicious; the main issue is supply-chain and credential/data exposure risk from the external CLI dependency.

Confidence: 81%Severity: 58%
Audit Metadata
Analyzed At
May 20, 2026, 04:40 AM
Package URL
pkg:socket/skills-sh/ruvnet%2Fruflo%2Ftrader-explain%2F@35ca1c0c3f9f3c797f0ae70b4114b6fa4c8d92b7
Security Audit — socket — trader-explain