etsy-tony-full-erank-listing

Warn

Audited by Socket on Sep 17, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core Etsy/eRank research purpose is plausible, but the required data flow through an unverifiable Clawlist Gemini endpoint and reliance on unverified local/harness tooling make the footprint broader than necessary. This looks more like a risky third-party workflow integration than confirmed malware, with the main concerns being supply-chain trust and off-platform handling of member-derived data.

Confidence: 86%Severity: 76%
AnomalyLOW
scripts/gemini_client.py

The fragment is an API client rather than an evident local malware payload. It deliberately uploads the configured API key, prompts, arbitrary payload data, and potentially local image files to https://clawlist.best. This is a significant supply-chain and privacy risk if the endpoint is untrusted, compromised, or not an approved service. No direct backdoor, command execution, persistence, destructive behavior, or obfuscated payload is present. The endpoint ownership, package provenance, and intended data-sharing policy should be independently verified before use.

Confidence: 94%Severity: 68%
Audit Metadata
Analyzed At
Sep 17, 2026, 03:47 AM
Package URL
pkg:socket/skills-sh/tony11081%2Fetsy-tony-skills-full%2Fetsy-tony-full-erank-listing%2F@c09e3edfb47ca7582c5c2f75149b9d9a36d20e3662458fe706e52d9745b5b6fb
Security Audit — socket — etsy-tony-full-erank-listing