music-industry-research

Warn

Audited by Socket on May 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s research capabilities and API-key use fit its stated purpose, but the data flow is inconsistent with the official documentation because it routes requests and credentials to a `vercel.app` deployment host instead of the documented first-party API domain. Scope is otherwise proportionate and there is no installer or obvious malware behavior, so this is better classified as a medium-risk trust and data-flow issue rather than confirmed maliciousness.

Confidence: 87%Severity: 61%
Audit Metadata
Analyzed At
May 10, 2026, 09:48 PM
Package URL
pkg:socket/skills-sh/recoupable%2Fskills%2Fmusic-industry-research%2F@ff0ae411626a176ca7bf5c3e85cd052912f337ae