ecom

Warn

Audited by Socket on Mar 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s stated purpose and local file flows are coherent for ecommerce analytics, and there is no evidence of credential harvesting or external data routing. However, the core capability relies on an undocumented local CLI/runtime whose provenance cannot be verified from the skill text or official docs, creating a mandatory high supply-chain risk even without stronger signs of malicious intent.

Confidence: 82%Severity: 72%
Audit Metadata
Analyzed At
Mar 20, 2026, 12:27 PM
Package URL
pkg:socket/skills-sh/takechanman1228%2Fclaude-ecom%2Fecom%2F@a006a29a56d95862e46484f1228c757ef493ab73