news-shopping
Warn
Audited by Socket on Apr 3, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill's purpose matches its search capability, but its trust model is weaker than expected. It uses an unpinned external CLI and routes requests through a non-official intermediary domain, creating moderate supply-chain and data-flow risk without clear evidence of outright malware.
Confidence: 83%Severity: 58%
Audit Metadata