pricing-finder

Warn

Audited by Socket on May 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's overall purpose is coherent and its optional API calls go to official services, so this is not strongly indicative of malware. However, it processes substantial untrusted web/search content while retaining command execution and file-write capability, and it relies on an unseen local script plus unpinned dependencies. Main risk is indirect prompt injection and execution scope, not credential theft or overt exfiltration.

Confidence: 85%Severity: 64%
Audit Metadata
Analyzed At
May 15, 2026, 05:54 PM
Package URL
pkg:socket/skills-sh/Varnan-Tech%2Fopendirectory%2Fpricing-finder%2F@74d07559d8a2dc10d555264ab5f6363013849b8d
Security Audit — socket — pricing-finder