apify-ecommerce

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core purpose aligns with Apify e-commerce extraction and the visible runtime path uses official Node functionality and an official Apify actor, so this is not clearly malicious. However, the skill is a third-party wrapper from a personal repo, reads APIFY_TOKEN from a local env file, and the actual helper script that receives the token is not provided, leaving credential/data-flow verification incomplete. Medium risk, not confirmed malware.

Confidence: 84%Severity: 57%
Audit Metadata
Analyzed At
Apr 28, 2026, 02:57 AM
Package URL
pkg:socket/skills-sh/diegosouzapw%2Fawesome-omni-skills%2Fapify-ecommerce%2F@8a34984f91e1672b6578d02c146f2e2321748590