Oathe Security Badge

Is veeramanikandanr48/portfolio-manager safe?

https://clawhub.ai/veeramanikandanr48/portfolio-manager

91
SAFE

This portfolio management skill appears legitimate and safe for installation. It provides comprehensive portfolio analysis functionality using Alpaca MCP integration with detailed documentation and reference materials. No malicious behavior or security vulnerabilities were detected during installation or analysis.

Category Scores

Prompt Injection 95/100 · 30%
Data Exfiltration 90/100 · 25%
Code Execution 90/100 · 20%
Clone Behavior 85/100 · 10%
Canary Integrity 95/100 · 10%
Behavioral Reasoning 90/100 · 5%

Findings (3)

INFO External Network Connections During Installation -10

The skill installation process made connections to external hosts including clawhub.ai (expected for skill verification) and other external IPs. All connections appear legitimate for skill installation and verification purposes.

INFO Python Script Present -10

The skill contains a Python script for testing Alpaca API connections. This appears to be a legitimate utility script for the portfolio management functionality.

INFO Standard Installation Network Activity -15

Network connections were made during installation for skill verification and dependency resolution. Behavior is consistent with legitimate skill installation processes.