trader-portfolio

Warn

Audited by Socket on May 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's finance purpose mostly matches its capabilities, but it depends on runtime install/execution of a third-party npm CLI with only partially verified provenance and produces financially consequential rebalance guidance. No direct credential theft or clear exfiltration is shown, but the combination of Bash+npx and autonomous portfolio advice creates meaningful security and operational risk.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
May 23, 2026, 03:21 AM
Package URL
pkg:socket/skills-sh/ruvnet%2Fruflo%2Ftrader-portfolio%2F@ca87b2752054b7b8f3efc3255ae323a8f60052be
Security Audit — socket — trader-portfolio