synthetic-users

Warn

Audited by Socket on Aug 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's main research-writing behavior is locally scoped and coherent, but it also instructs transitive installation of more skills from a personal GitHub repository via an unpinned `npx` CLI flow. There is no direct credential harvesting or exfiltration here, yet the install-and-expand trust chain is disproportionate to a synthetic persona guide and raises meaningful supply-chain risk.

Confidence: 92%Severity: 74%
Audit Metadata
Analyzed At
Aug 29, 2026, 05:24 AM
Package URL
pkg:socket/skills-sh/pedroromeroluna%2Fai-first-product-skills%2Fsynthetic-users%2F@04ea4877e2b20d4465760c224f5386f1e6fa298e91d67da13815734da704187e
Security Audit — socket — synthetic-users