Back to plugin

Security audit

Stock Analysis

Security checks for vulnerabilities and agentic risk

Overview

This stock-analysis package uses disclosed local Python tools, market-data APIs, and optional local signal history in ways that match its stated purpose.

Before installing, understand that setup may install Python dependencies, and tool use may send stock symbols, search queries, URLs, and configured API keys to market-data or search providers. The package can also keep local records of generated buy/sell signals if the host agent chooses to use that feature; treat any financial analysis as informational rather than a guarantee.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
dist/index.js:4430
Evidence
const { stdout } = await exec(bin, argv, { maxBuffer: 32 * 1024 * 1024 });

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
index.ts:14
Evidence
const { stdout } = await exec(bin, argv, { maxBuffer: 32 * 1024 * 1024 });

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/setup-python.mjs:18
Evidence
execSync(cmd, { stdio: "pipe", timeout: 300_000 });