fix-demos

Warn

Audited by Socket on Mar 27, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities broadly match its stated purpose and the main endpoints are same-org, so this is not strongly indicative of malware. However, it reads raw tokens, ingests untrusted website content, sends company URLs to a third-party API, and can autonomously rewrite/publish demos and update CRM records, making the overall security risk medium.

Confidence: 85%Severity: 58%
Audit Metadata
Analyzed At
Mar 27, 2026, 01:05 PM
Package URL
pkg:socket/skills-sh/psquared-development%2Fpsquared-skills%2Ffix-demos%2F@49b6c844c3022e30eef19289665f7c2458ea7d32
Security Audit — socket — fix-demos