amazon-assistant

Warn

Audited by Socket on Aug 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's core behavior is coherent with its stated Amazon-assistant purpose, but it relies on highly sensitive cookie-based session reuse, browser-cookie export fallback, and consequential account automation. There is no clear third-party credential exfiltration or malware behavior, yet the credential scope and account-action footprint make it a medium-high security risk AI skill.

Confidence: 87%Severity: 71%
Audit Metadata
Analyzed At
Aug 4, 2026, 07:31 PM
Package URL
pkg:socket/skills-sh/cosmicstack-labs%2Fmercury-agent-skills%2Famazon-assistant%2F@64fc0d0d7a58d4dc24caa265fd8fb05b5f4efd2390665c509e8c97eef9c2768b
Security Audit — socket — amazon-assistant