oss-bounty-finder

Warn

Audited by Socket on May 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose and capabilities mostly align, and the TinyFish install path appears official, so this is not confirmed malware. However, it delegates broad web automation and extracted-content handling to a third-party CLI/service, forwards an API key to that service, and processes substantial untrusted external content, creating meaningful privacy, supply-chain, and prompt-injection risk.

Confidence: 85%Severity: 57%
Audit Metadata
Analyzed At
May 10, 2026, 08:42 AM
Package URL
pkg:socket/skills-sh/tinyfish-io%2Ftinyfish-cookbook%2Foss-bounty-finder%2F@83ef5309e6b0999c8ae757f908f9daae8f213ea8