copywrite

Warn

Audited by Socket on Jul 5, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose is benign and aligned with copywriting, but the skill instructs installation of external third-party skills through an unseen local Python wrapper. That transitive install chain and unverifiable installer behavior make the trust model disproportionate to a writing-assistance skill, even without direct evidence of credential theft or malware.

Confidence: 84%Severity: 62%
Audit Metadata
Analyzed At
Jul 5, 2026, 04:25 PM
Package URL
pkg:socket/skills-sh/alvarovillalbaa%2Fplugins%2Fcopywrite%2F@e6d7ae5af37c3e3092a6ca5daec1e7c6e8f4d1784b5f882c223c4157230d0353
Security Audit — socket — copywrite