product-skills

Warn

Audited by Socket on Sep 3, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s stated purpose is benign and its local Python tooling appears proportionate, but the Codex setup uses transitive skill installation from a personal GitHub repo through npx. That raises medium supply-chain and trust-chain risk even without evidence of credential theft or malicious data flows.

Confidence: 87%Severity: 58%
AnomalyLOW
research-summarizer/SKILL.md

SUSPICIOUS. The stated capability is benign and proportionate for a research summarization skill, and the text shows no credential harvesting or exfiltration behavior. However, the installation provenance is inconsistent: personal GitHub clone source, unresolved publisher mismatch, and questionable OpenClaw install syntax create medium supply-chain risk that does not fit a cleanly distributed end-user skill.

Confidence: 87%Severity: 57%
Audit Metadata
Analyzed At
Sep 3, 2026, 02:34 PM
Package URL
pkg:socket/skills-sh/afaizalam2003%2Fmaster-claude-skill%2Fproduct-skills%2F@353f74587a1d83c81b380ce2755d6c93b97a6fc9c34f815c3e3b8762a35994de
Security Audit — socket — product-skills