customer-persona

Warn

Audited by Socket on May 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core persona-research behavior is coherent, but the skill requires transitive installation of another skill plus an external CLI/service stack, which meaningfully increases trust and credential-handling risk relative to its simple stated purpose. Data flows appear aligned with research and avatar generation rather than overt theft, so this is not confirmed malware.

Confidence: 85%Severity: 58%
Audit Metadata
Analyzed At
May 19, 2026, 07:50 AM
Package URL
pkg:socket/skills-sh/inference-sh%2Fskills%2Fcustomer-persona%2F@cd33ef2b9e7ac90d64a96d1cb7e82e12bb480f88
Security Audit — socket — customer-persona