competitor-monitoring

Warn

Audited by Socket on Mar 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's stated purpose matches its research and Extruct-table workflow, but its full execution is delegated to another skill, creating a transitive trust gap. On its own it does not show malware or credential theft, yet the combination of broad external-content ingestion and offloaded API/credential handling makes it a medium-risk AI skill until the extruct-api dependency is reviewed.

Confidence: 81%Severity: 56%
Audit Metadata
Analyzed At
Mar 22, 2026, 02:43 PM
Package URL
pkg:socket/skills-sh/extruct-ai%2Fgtm-skills%2Fcompetitor-monitoring%2F@100596ed3716b45cc525efc690dd6447073a1f3f
Security Audit — socket — competitor-monitoring