ecomseer

Warn

Audited by Socket on May 10, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The direct EcomSeer API calls fit the skill's purpose, but the deep-research workflow materially changes the trust boundary by forwarding the user's EcomSeer API key, query, and context to AdMapix, a separate service not necessary for basic analytics. This cross-vendor credential routing is the main risk and makes the overall footprint disproportionate to the stated purpose.

Confidence: 89%Severity: 82%
Audit Metadata
Analyzed At
May 10, 2026, 03:18 AM
Package URL
pkg:socket/skills-sh/fly0pants%2Fecomseer-skill%2Fecomseer%2F@e6133058c7ac025b96f11c025200b1bec5fe99ab