swiggy-cart

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's stated purpose is coherent, but its core mechanism relies on an unverifiable `swiggy` CLI that is not the install path Swiggy publicly documents. Because that binary would receive authenticated account access and can perform cart mutations, the skill carries high security risk despite otherwise narrow functionality and a sensible approval gate for clear-cart.

Confidence: 84%Severity: 84%
Audit Metadata
Analyzed At
Apr 28, 2026, 03:23 PM
Package URL
pkg:socket/skills-sh/HKTITAN%2Fswiggy-cli%2Fswiggy-cart%2F@04653a64d5a46a8dbcc7fb9a72022688f933f7d7