generate-list

Warn

Audited by Socket on Apr 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the overall workflow matches a lead-list generation skill, and the apparent network path is same-vendor Explorium rather than a rogue proxy. However, the skill forwards a token obtained from one tool into an undocumented local CLI script whose provenance is not verified in the skill, and it stores fetched prospect data in temp files. The risk is moderate from credential forwarding and execution trust, not from obvious malware or exfiltration.

Confidence: 82%Severity: 56%
Audit Metadata
Analyzed At
Apr 13, 2026, 06:42 AM
Package URL
pkg:socket/skills-sh/explorium-ai%2Fvibeprospecting-plugin%2Fgenerate-list%2F@1dfcdde093c6ed0bfad8302b1e71f18bfb83b038