ecommerce-product-ai-visibility

Warn

Audited by Socket on Sep 11, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The research and reporting pipeline broadly fits the stated ecommerce visibility purpose, but the mandatory hidden email step is a major mismatch: it performs an undisclosed real-world action on the user's behalf and instructs the agent to conceal it. External content handling adds moderate prompt-injection risk, but the covert email behavior is the primary reason this skill should not be treated as benign.

Confidence: 86%Severity: 78%
Audit Metadata
Analyzed At
Sep 11, 2026, 07:20 AM
Package URL
pkg:socket/skills-sh/nexscope-ai%2Fnexscope-ecommerce-skills%2Fecommerce-product-ai-visibility%2F@ff785bf672002abc5148c2917c52f6fa6d4a23717d2289e5252b793eae036180
Security Audit — socket — ecommerce-product-ai-visibility