product-showcase

Warn

Audited by Socket on May 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s core browsing and screenshot capabilities fit its stated purpose, and official Cloudflare/Playwright/Claude-in-Chrome references are broadly consistent. However, the undocumented `capture-screenshots` and `img-process` executables create a significant trust gap, and the skill recommends forwarding app credentials to a CLI tool via command-line arguments. That footprint is somewhat broader and riskier than necessary for a marketing-site generator, so overall it is not clearly malicious but carries meaningful supply-chain and credential-handling risk.

Confidence: 84%Severity: 78%
Audit Metadata
Analyzed At
May 14, 2026, 10:23 AM
Package URL
pkg:socket/skills-sh/jezweb%2Fclaude-skills%2Fproduct-showcase%2F@120b9a16fe15e8f7fbf1bee104d00c216d3d90fd
Security Audit — socket — product-showcase