bloome-finance-plugin avatar

bloome-finance-plugin

PluginFinanceAI ModelsWeb searchFile
Verification
L1 · Found
Security
Medium
Health
Active
Trust
Unrated

What it doesAI

Professional financial research plugin that generates structured, evidence-based investment reports for AI assistants.

  • Expert-first research across institutional and official sources
  • Decomposes questions into parallel research modules
  • Generates traceable HTML reports with validation

AI-generated from the repo README — for reference only.

Installation

dsh plugin --profile web add github:ArcoCodes/bloome-finance-plugin

Install method: GitHub · not yet tested in container (L3+)

Compatibility

DSH VersionStatus
not statedDeclared — not tested

Requirements

  • • Node.js: not stated
  • • DSH: declared "not stated"
  • • External credentials: none detected

Security Report

Automated static scan, not manual review.

DSH.SO VETMEDIUM981aa8
Automated review · daily
MEDIUM

Vet verdict is suspicious: findings need human review (exfiltration endpoints, file deletion, etc.).

0 critical·1 high·14 medium·0 score
plugin version
scanned commit981aa82cf82f2026-08-21
latest commit981aa82cf82f
vet verdictsuspicious · gitscore 0

Vet is an AST static scan (npm artifact or git source).

Disclaimer: automated static analysis, not a security guarantee. Always review what you install.

Risk details

RiskRuleLocationDescription
high
R2
finance-client.cjs:7
require('node:child_process') 危险内置模块(执行/网络能力触达)
medium
R2
host.mjs:9
require() 动态模块加载(npm 包内能力触达)
medium
R9
generate-runtime-manifests.mjs:13
正则嵌套量词(ReDoS 风险:(a+)+ 类指数回溯)
medium
R2
finance-client.cjs:3
require('node:crypto') 标准内置模块
medium
R2
finance-client.cjs:4
require('node:fs') 标准内置模块
Heuristic static scan — may produce false positives. Review the source yourself before trusting.

Activity

Last commit 2026-08-17 · activity: Active

• Repo created: 2026-08-21

• Stars: ★ 0 · Forks: 0

• Health: Active — committed within last 30 days

Source

GitHub: github.com/ArcoCodes/bloome-finance-plugin

Was this page helpful?