ecommerce-amazon-product-database

Warn

Audited by Socket on Sep 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core capability fits the stated purpose, but the skill routes credentials and data through Nexscope rather than a first-party Jungle Scout API and has inconsistent endpoint documentation. Mandatory local response persistence also broadens exposure. No clear malware behavior or exploit logic is present, but the proxy-based data flow and documentation mismatch create medium security risk.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Sep 14, 2026, 04:13 AM
Package URL
pkg:socket/skills-sh/nexscope-ai%2Fnexscope-ecommerce-skills%2Fecommerce-amazon-product-database%2F@02c03e30c0ea5e4a111a035637cb7623ac0b7b66523f110c2760725d409c9c22
Security Audit — socket — ecommerce-amazon-product-database