product-opportunity-finder

Warn

Audited by Socket on Jun 26, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose and capabilities mostly align, and there is no download-execute chain or obvious malware behavior. The main concern is data-flow integrity: all marketplace access is proxied through Nexscope and the base URL is configurable, so credentials and query data depend on a third-party endpoint rather than official APIs.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
Jun 26, 2026, 04:16 AM
Package URL
pkg:socket/skills-sh/nexscope-ai%2Fnexscope-ecommerce-skills%2Fproduct-opportunity-finder%2F@c62ff29a5898ba7a98158726c0f17d6e0fb2907db539d3762fbb7481392a7af4
Security Audit — socket — product-opportunity-finder