content-engine

Warn

Audited by Socket on Jul 1, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
skills/content-engine-autopilot/SKILL.md

SUSPICIOUS: The core browser-orchestration purpose is coherent, but the install trust is not. The skill depends on a third-party browser automation CLI with a publisher mismatch in the instructions, then uses it to manage persistent authenticated sessions for multiple external services. No clear malicious exfiltration is shown, but the provenance inconsistency plus credential-like session handling make the skill medium/high risk.

Confidence: 84%Severity: 63%
SecurityMEDIUM
skills/content-engine-loop/SKILL.md
Audit Metadata
Analyzed At
Jul 1, 2026, 03:35 PM
Package URL
pkg:socket/skills-sh/broomva%2Fskills%2Fcontent-engine%2F@acb6f55da15a6177e2efee00705aff7d561b9561c03b4360ced46cd9aa8d907c
Security Audit — socket — content-engine