npm-package-comparator

Warn

Audited by Socket on Sep 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s stated purpose is plausible, and the install/auth flow appears to match TinyFish’s official docs and npm package. However, the capability is not tightly scoped: a simple npm-package comparison task is routed through a third-party authenticated CLI and TinyFish-hosted infrastructure instead of using direct public sources. This is not confirmed malware, but it is a disproportionate trust and data-flow expansion for the claimed purpose.

Confidence: 89%Severity: 64%
Audit Metadata
Analyzed At
Sep 28, 2026, 01:05 AM
Package URL
pkg:socket/skills-sh/tinyfish-io%2Ftinyfish-cookbook%2Fnpm-package-comparator%2F@2500a8b0ec16d08b782ff95e2700efb5affd9338b906d671fba5c89fdb55140c
Security Audit — socket — npm-package-comparator