insider-sentiment-aggregator
Warn
Audited by Socket on Mar 17, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The stated purpose is coherent for a financial-research skill, and no credential harvesting, exfiltration endpoint, or autonomous trading behavior is visible. The main issue is install/execution trust: it tells the agent to run unseen Python scripts from a sibling local toolkit with unverifiable provenance and undisclosed data-query behavior, so the skill has moderate security risk despite limited evidence of malicious intent.
Confidence: 84%Severity: 58%
Audit Metadata