tech-advisor

Warn

Audited by Socket on Jun 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose is coherent with web research for tech recommendations, but it expands trust to external runtime-installed packages and a third-party fetch proxy. Risk comes from supply-chain hygiene and untrusted-content processing rather than clear malicious intent; no credential harvesting, secret-file access, or disproportionate permissions are present in the instructions shown.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 13, 2026, 01:25 AM
Package URL
pkg:socket/skills-sh/CyranoB%2Fweb-forager%2Ftech-advisor%2F@2deedd7a5cf4bf4569cd9bac85e2eaaa5e2600d4e4c7028d948e483d406bb1de
Security Audit — socket — tech-advisor