npm-package-comparator
Warn
Audited by Socket on Sep 28, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill’s stated purpose is plausible, and the install/auth flow appears to match TinyFish’s official docs and npm package. However, the capability is not tightly scoped: a simple npm-package comparison task is routed through a third-party authenticated CLI and TinyFish-hosted infrastructure instead of using direct public sources. This is not confirmed malware, but it is a disproportionate trust and data-flow expansion for the claimed purpose.
Confidence: 89%Severity: 64%
Audit Metadata