ahrefs
Warn
Audited by Socket on Jun 28, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill's Ahrefs-focused capabilities are coherent, and the npm-based CLI install is not inherently malicious. However, the core integration depends on a third-party intermediary that stores tokens and brokers all Ahrefs access, which creates significant data-flow and credential-trust risk beyond a direct official Ahrefs integration.
Confidence: 88%Severity: 68%
Audit Metadata