haul

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core behavior is mostly coherent with a product-image collection skill, and it includes several proportional safety boundaries. The main concern is data-flow integrity: it mixes official APIs with SerpAPI, a third-party proxy that unnecessarily intermediates search traffic, while also enabling broad untrusted web ingestion, authenticated-session handoff, local writes, and downstream sharing. No evidence of malware or deceptive payload installation is present, but the skill has medium security risk due to third-party routing and agentic web-content handling.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
Apr 30, 2026, 10:15 AM
Package URL
pkg:socket/skills-sh/simota%2Fagent-skills%2Fhaul%2F@0cf8dd407816c2d11caf5bcc95fcab312c6d70e9