edge-hint-extractor

Warn

Audited by Socket on Apr 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core skill is coherent and mostly local, but the optional --llm-ideas-cmd mode expands the trust boundary to arbitrary external code without provenance or verification. Not malicious on its face, yet the external CLI hook creates medium security risk disproportionate to a simple hint-extraction workflow when safer file-based augmentation is already supported.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Apr 12, 2026, 08:31 PM
Package URL
pkg:socket/skills-sh/tradermonty%2Fclaude-trading-skills%2Fedge-hint-extractor%2F@5823d5e8b3a87783296ed0674e41b42fba87b58b