swiggy-track

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose is coherent and the commands are read-only, but the skill's real footprint depends on a non-official external CLI that appears to consume Swiggy session cookies. Because the binary provenance is not established in the skill and evidence points to a personal repo, this creates a high supply-chain and credential-handling risk disproportionate to a simple order-tracking helper.

Confidence: 87%Severity: 82%
Audit Metadata
Analyzed At
Apr 28, 2026, 03:23 PM
Package URL
pkg:socket/skills-sh/HKTITAN%2Fswiggy-cli%2Fswiggy-track%2F@7ab016a43283faae6781cee1d9f2a427063955b7