mercadona-cli-shopping
Warn
Audited by Socket on Sep 20, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is broadly aligned with grocery automation, but its footprint is higher risk than a typical shopping helper. Main concerns are third-party CLI trust (especially raw GitHub pipe-to-shell), browser-session token extraction, durable credential storage, and autonomous real-world order submission. No clear evidence of credential exfiltration beyond Mercadona, so this is not confirmed malware.
Confidence: 90%Severity: 76%
Audit Metadata