competitive-ads-extractor

Warn

Audited by Socket on May 11, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the visible wrapper is narrowly scoped and not overtly malicious, but it instructs the agent to install an upstream skill bundle from an unpinned GitHub path. That transitive installation step is the main risk; absent the upstream bundle contents here, the trust chain is broader than necessary for a simple catalogue entry.

Confidence: 88%Severity: 56%
Audit Metadata
Analyzed At
May 11, 2026, 11:03 AM
Package URL
pkg:socket/skills-sh/nexu-io%2Fopen-design%2Fcompetitive-ads-extractor%2F@2d854c535798043e8c448b9a065423439355b815