customer-persona

Warn

Audited by Socket on May 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s stated purpose is coherent, but its footprint is broader than necessary because it requires a third-party CLI with login, grants broad Bash access, and encourages transitive skill installation. The main concern is install/execution trust and external data routing rather than confirmed malicious behavior.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
May 28, 2026, 11:40 AM
Package URL
pkg:socket/skills-sh/inference-sh-9%2Fskills%2Fcustomer-persona%2F@cd33ef2b9e7ac90d64a96d1cb7e82e12bb480f88
Security Audit — socket — customer-persona