product-discovery

Warn

Audited by Socket on May 5, 2026

1 alert found:

Anomaly
AnomalyLOW
skill.yaml

From the provided manifest alone, there is no direct evidence of malicious payloads or obfuscation. However, the package is configured to execute bundled shell code (scripts/search.sh) with network access and a required secret API key, which creates a realistic risk surface for credential mishandling or unexpected outbound behavior. A full security determination requires inspection of the referenced shell scripts to confirm they only perform intended authenticated API calls and do not log or exfiltrate the API key or perform unauthorized system actions.

Confidence: 42%Severity: 60%
Audit Metadata
Analyzed At
May 5, 2026, 06:58 PM
Package URL
pkg:socket/skills-sh/channel3-ai%2Fskills%2Fproduct-discovery%2F@980c4626a80fc51ec42e391b832fb3f957f72ff2