a-share-paper-trading

Warn

Audited by Socket on Sep 19, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/paper_trading/service.py

No clear malicious or supply-chain attack behavior is present in this fragment. The code is a straightforward paper-trading HTTP server, but it exposes sensitive state-changing operations without authentication or authorization and lacks request-size and robust input controls. Deployment on an untrusted network would create a high-impact access-control risk. The incomplete final line also prevents confirmation that the fragment is directly runnable.

Confidence: 98%Severity: 83%
Audit Metadata
Analyzed At
Sep 19, 2026, 03:21 PM
Package URL
pkg:socket/skills-sh/shouldnotappearcalm%2Fa-share-skill%2Fa-share-paper-trading%2F@ce75c7cf717b42249e9fb97efc1246ce241fbb6d8ba4ac33c6a628fde5d28083
Security Audit — socket — a-share-paper-trading