viral

Warn

Audited by Socket on Apr 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core behavior matches a content ideation skill, but it asks the user to install a third-party MCP server via npx and provide an Apify token to that external process. The main risk is supply-chain and credential-forwarding exposure, plus prompt-injection risk from broad untrusted research sources; there is no strong evidence of overt malware or intentional exfiltration.

Confidence: 86%Severity: 78%
Audit Metadata
Analyzed At
Apr 16, 2026, 07:44 AM
Package URL
pkg:socket/skills-sh/tenfoldmarc%2Fviral-skill%2Fviral%2F@6018b7ec91d0c1eeb83a15e6885b753c816d7248
Security Audit — socket — viral