doordash

Warn

Audited by Socket on Jul 25, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose and file access are mostly coherent for family food ordering, and the approval gate is a meaningful safeguard, but it relies on an undocumented/unverifiable local dd-cli binary to perform authenticated ordering and card charging. That black-box executable and the real-world purchase capability make this a high security-risk skill even without clear evidence of malware.

Confidence: 84%Severity: 78%
Audit Metadata
Analyzed At
Jul 25, 2026, 05:25 PM
Package URL
pkg:socket/skills-sh/idanbeck%2Fclaude-skills%2Fdoordash%2F@fef4b4ccb7b117b79c9d3b0713e5361050edfe6f4ffd71957a3fa2d13e8d5b4b
Security Audit — socket — doordash