ecom
Warn
Audited by Socket on Mar 20, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s stated purpose and local file flows are coherent for ecommerce analytics, and there is no evidence of credential harvesting or external data routing. However, the core capability relies on an undocumented local CLI/runtime whose provenance cannot be verified from the skill text or official docs, creating a mandatory high supply-chain risk even without stronger signs of malicious intent.
Confidence: 82%Severity: 72%
Audit Metadata