swiggy-cart
Warn
Audited by Socket on Apr 28, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill's stated purpose is coherent, but its core mechanism relies on an unverifiable `swiggy` CLI that is not the install path Swiggy publicly documents. Because that binary would receive authenticated account access and can perform cart mutations, the skill carries high security risk despite otherwise narrow functionality and a sensible approval gate for clear-cart.
Confidence: 84%Severity: 84%
Audit Metadata